{continue]
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EasyDVDPlayer"="C:\Program Files\EasyDVD\EasyDVD.exe" [2002-04-22 10:32 306176]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [ ]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-02-10 21:11 77824]
"PcAhH"="C:\WINDOWS\cssbv.exe" [ ]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 00:56 15360]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^MyWebSearch Email Plugin.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\MyWebSearch Email Plugin.lnk
backup=C:\WINDOWS\pss\MyWebSearch Email Plugin.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^xx^Start Menu^Programs^Startup^MyWebSearch Email Plugin.lnk]
path=C:\Documents and Settings\xx\Start Menu\Programs\Startup\MyWebSearch Email Plugin.lnk
backup=C:\WINDOWS\pss\MyWebSearch Email Plugin.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2007-12-02 11:32 163840 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
--a------ 2004-05-14 08:47 67072 C:\WINDOWS\SOUNDMAN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
--a------ 2007-11-30 16:56 1266936 d:\igre\steam\steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2007-07-30 17:52 68856 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
S3 AC2003;AC2003;C:\WINDOWS\system32\Drivers\AC2003.sys [2003-12-10 08:21]
.
Contents of the 'Scheduled Tasks' folder
"2008-01-24 23:00:00 C:\WINDOWS\Tasks\At1.job"
- C:\WINDOWS\system32\DtHSJMgM.exe
"2008-01-26 08:00:00 C:\WINDOWS\Tasks\At10.job"
- C:\WINDOWS\system32\DtHSJMgM.exe
"2008-01-29 09:00:00 C:\WINDOWS\Tasks\At11.job"
- C:\WINDOWS\system32\DtHSJMgM.exe
"2008-01-26 10:00:00 C:\WINDOWS\Tasks\At12.job"
- C:\WINDOWS\system32\DtHSJMgM.exe
"2008-01-27 11:00:00 C:\WINDOWS\Tasks\At13.job"
- C:\WINDOWS\system32\DtHSJMgM.exe
"2008-01-27 12:00:00 C:\WINDOWS\Tasks\At14.job"
- C:\WINDOWS\system32\DtHSJMgM.exe
"2008-01-27 12:59:59 C:\WINDOWS\Tasks\At15.job"
- C:\WINDOWS\system32\DtHSJMgM.exe
"2008-01-28 14:00:00 C:\WINDOWS\Tasks\At16.job"
- C:\WINDOWS\system32\DtHSJMgM.exe
"2008-01-28 15:00:00 C:\WINDOWS\Tasks\At17.job"
- C:\WINDOWS\system32\DtHSJMgM.exe
"2008-01-28 16:00:00 C:\WINDOWS\Tasks\At18.job"
- C:\WINDOWS\system32\DtHSJMgM.exe
"2008-01-28 17:00:00 C:\WINDOWS\Tasks\At19.job"
- C:\WINDOWS\system32\DtHSJMgM.exe
"2008-01-12 00:00:00 C:\WINDOWS\Tasks\At2.job"
- C:\WINDOWS\system32\DtHSJMgM.exe
"2008-01-28 18:00:00 C:\WINDOWS\Tasks\At20.job"
- C:\WINDOWS\system32\DtHSJMgM.exe
"2008-01-28 19:00:00 C:\WINDOWS\Tasks\At21.job"
- C:\WINDOWS\system32\DtHSJMgM.exe
"2008-01-28 20:00:00 C:\WINDOWS\Tasks\At22.job"
- C:\WINDOWS\system32\DtHSJMgM.exe
"2008-01-27 21:00:00 C:\WINDOWS\Tasks\At23.job"
- C:\WINDOWS\system32\DtHSJMgM.exe
"2008-01-26 22:00:00 C:\WINDOWS\Tasks\At24.job"
- C:\WINDOWS\system32\DtHSJMgM.exe
"2007-11-11 01:01:00 C:\WINDOWS\Tasks\At3.job"
- C:\WINDOWS\system32\DtHSJMgM.exe
"2007-11-11 02:01:00 C:\WINDOWS\Tasks\At4.job"
- C:\WINDOWS\system32\DtHSJMgM.exe
"2007-10-06 02:01:00 C:\WINDOWS\Tasks\At5.job"
- C:\WINDOWS\system32\DtHSJMgM.exe
"2007-10-06 03:01:00 C:\WINDOWS\Tasks\At6.job"
- C:\WINDOWS\system32\DtHSJMgM.exe
"2007-12-10 05:00:00 C:\WINDOWS\Tasks\At7.job"
- C:\WINDOWS\system32\DtHSJMgM.exe
"2007-12-27 06:00:00 C:\WINDOWS\Tasks\At8.job"
- C:\WINDOWS\system32\DtHSJMgM.exe
"2008-01-26 07:00:00 C:\WINDOWS\Tasks\At9.job"
- C:\WINDOWS\system32\DtHSJMgM.exe
"2008-01-29 09:16:00 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-01-29 10:18:55
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
.
**************************************************************************
.
Completion time: 2008-01-29 10:19:30 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-29 09:19:26
// I had a problem with a file c:\WINDOWS\system32\cdosy.dll, which was deleted (according to the log report). So, is my problem already fixed?