((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
Note empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“TOSCDSPD”=“C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe” [2004-12-30 03:32 65536]
“ctfmon.exe”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-10 08:00 15360]
“MSMSGS”=“C:\Program Files\Messenger\msmsgs.exe” [2004-10-13 12:24 1694208]
“Skype”=“C:\Program Files\Skype\Phone\Skype.exe” [2008-02-06 19:37 21898024]
“swg”=“C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe” [2008-04-09 10:00 68856]
“SUPERAntiSpyware”=“C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe” [2008-08-19 23:34 1576176]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“ehTray”=“C:\WINDOWS\ehome\ehtray.exe” [2005-08-05 16:56 64512]
“ATIPTA”=“C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe” [2006-03-22 00:05 344064]
“SynTPEnh”=“C:\Program Files\Synaptics\SynTP\SynTPEnh.exe” [2006-03-02 04:02 761948]
“DLA”=“C:\WINDOWS\System32\DLA\DLACTRLW.EXE” [2005-10-06 08:20 122940]
“SmoothView”=“C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe” [2005-04-26 19:13 122880]
“Tvs”=“C:\Program Files\Toshiba\Tvs\TvsTray.exe” [2006-02-02 15:11 73728]
“PadTouch”=“C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe” [2005-12-06 01:06 1077322]
“THotkey”=“C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe” [2006-08-25 16:47 356352]
“LtMoh”=“C:\Program Files\ltmoh\Ltmoh.exe” [2004-08-17 15:37 184320]
“Start RF Wireless Mouse”=“C:\Program Files\RF Wireless Mouse\cm20.exe” [2002-01-31 10:59 61440]
“Symantec PIF AlertEng”=“C:\Program Files\Common Files\Symantec Shared\PIF{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe” [2007-11-28 20:51 583048]
“lxdfmon.exe”=“C:\Program Files\Lexmark 6500 Series\lxdfmon.exe” [2007-06-11 09:53 455600]
“lxdfamon”=“C:\Program Files\Lexmark 6500 Series\lxdfamon.exe” [2007-06-01 04:06 20480]
“Lexmark 6500 Series Fax Server”=“C:\Program Files\Lexmark 6500 Series\fm3032.exe” [2007-06-11 09:56 308144]
“BigDog303”=“C:\WINDOWS\VM303_STI.EXE” [2005-10-25 00:56 61440]
“SunJavaUpdateSched”=“C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe” [2008-06-10 04:27 144784]
“RTHDCPL”=“RTHDCPL.EXE” [2006-05-04 18:59 16206848 C:\WINDOWS\RTHDCPL.exe]
“AGRSMMSG”=“AGRSMMSG.exe” [2005-12-12 19:50 88204 C:\WINDOWS\agrsmmsg.exe]
“NDSTray.exe”=“NDSTray.exe” [BU]
“TPSMain”=“TPSMain.exe” [2005-06-01 00:00 282624 C:\WINDOWS\system32\TPSMain.exe]
“CFSServ.exe”=“CFSServ.exe” [BU]
[HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“C:\WINDOWS\system32\CTFMON.EXE” [2004-08-10 08:00 15360]
C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup
IEHOME.LNK - C:\Documents and Settings\Default User\Local Settings\Temp\iehome.bat [2006-12-13 14:45:36 298]
C:\Documents and Settings\Administrator\Start Menu\Programs\Startup
IEHOME.LNK - C:\Documents and Settings\Default User\Local Settings\Temp\iehome.bat [2006-12-13 14:45:36 298]
C:\Documents and Settings\Christopher\Start Menu\Programs\Startup
Microsoft Office OneNote 2003 Quick Launch.lnk - C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE [2004-06-12 00:57:52 59080]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
RAMASST.lnk - C:\WINDOWS\system32\RAMASST.exe [2006-09-14 18:48:02 155648]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
“InstallVisualStyle”= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
“InstallTheme”= C:\WINDOWS\Resources\Themes\Royale.theme
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
“{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}”= “C:\Program Files\SUPERAntiSpyware\SASSEH.DLL” [2008-05-13 10:13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify!SASWinLogon]
2008-07-23 16:28 352256 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dllschannel.dlldigest.dllmsnsspc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
“AntiVirusDisableNotify”=dword:00000001
“AntiVirusOverride”=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
“DisableMonitoring”=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
“DisableMonitoring”=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
“DisableMonitoring”=dword:00000001
[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
“%windir%\system32\sessmgr.exe”=
“C:\Program Files\Messenger\msmsgs.exe”=
“%windir%\Network Diagnostic\xpnetdiag.exe”=
“C:\WINDOWS\system32\lxdfcoms.exe”=
“C:\Program Files\Lexmark 6500 Series\lxdfamon.exe”=
“C:\Program Files\Lexmark 6500 Series\frun.exe”=
“C:\Program Files\Abbyy FineReader 6.0 Sprint\Scan\ScanMan6.exe”=
“C:\Program Files\Lexmark 6500 Series\lxdfmon.exe”=
“C:\WINDOWS\system32\lxdfcfg.exe”=
“C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdfpswx.exe”=
“C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdftime.exe”=
“C:\Program Files\Lexmark 6500 Series\LXDFFax.exe”=
“C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdfjswx.exe”=
“C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdfwbgw.exe”=
“C:\Program Files\Skype\Phone\Skype.exe”=
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 10:35]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 10:37]
R2 lxdf_device;lxdf_device;C:\WINDOWS\system32\lxdfcoms.exe [2007-05-29 02:06]
R2 lxdfCATSCustConnectService;lxdfCATSCustConnectService;C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\lxdfserv.exe [2007-05-29 02:06]
.
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = www.hotmail.com
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-29 16:48:05
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe
→ ?:\WINDOWS\system32\urlmon.dll
→ ?:\WINDOWS\system32\urlmon.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\acs.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\WINDOWS\ehome\ehrecvr.exe
C:\WINDOWS\ehome\ehSched.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdfserv.exe
C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\ehome\ehmsas.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\Synaptics\SynTP\Toshiba.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSServ.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\WINDOWS\system32\verclsid.exe
.
.
Completion time: 2008-08-29 16:52:33 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-29 20:52:28
Pre-Run: 33,837,121,536 bytes free
Post-Run: 36,317,757,440 bytes free
192 — E O F — 2008-08-14 11:46:54
thank you!!!