SDFix: Version 1.115
Run by Administrator on 2008-04-12 at 13:53
Microsoft Windows XP [Wersja 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting...
Normal Mode:
Checking Files:
No Trojan Files Found
Removing Temp Files...
ADS Check:
C:\WINDOWS
No streams found.
C:\WINDOWS\system32
No streams found.
C:\WINDOWS\system32\svchost.exe
No streams found.
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.
Final Check:
catchme 0.3.1351.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-12 13:57:41
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:2df9c43f
"s2"=dword:110480d0
"h0"=dword:00000003
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"p0"="E:\Programy\Alcohol 120\"
"h0"=dword:00000001
"ujdew"=hex:65,23,3c,f8,3f,2e,7d,9d,78,ff,c3,7f,f1,cf,fa,23,d7,50,03,8d,86,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC]
"h0"=dword:00000002
"hdf12"=hex:83,30,e9,3f,3e,63,b7,34,ab,c1,e4,f3,d4,c7,ba,90,4c,1d,50,bd,55,..
"p0"="C:\Program Files\DAEMON Tools Pro\"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001]
"a0"=hex:20,01,00,00,8f,50,7e,22,8e,f9,aa,33,e3,83,fb,7f,f1,a4,88,3e,d1,..
"hdf12"=hex:87,08,d7,9a,af,0f,09,1b,4a,4d,1f,6f,e4,bb,32,ea,b7,82,d6,66,8e,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0]
"hdf12"=hex:e8,d6,a6,d1,9d,4f,23,c6,30,22,49,b1,a5,b9,bf,eb,c8,f9,9d,a9,8d,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1]
"hdf12"=hex:fa,a0,cd,09,77,3b,de,6f,ca,53,c5,2d,66,ae,a0,5d,b6,7d,2e,ff,2c,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq2]
"hdf12"=hex:e8,d6,a6,d1,9d,4f,23,c6,30,22,49,b1,a5,b9,bf,eb,c8,f9,9d,a9,8d,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq3]
"hdf12"=hex:80,fa,7a,37,de,2a,db,68,24,9f,59,22,a8,1c,5d,87,ba,91,1e,11,2e,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002]
"a0"=hex:20,01,00,00,3d,73,72,22,da,8f,60,c7,05,88,64,58,ea,21,a9,97,40,..
"hdf12"=hex:e7,49,f7,41,90,bd,95,97,09,9e,a9,2d,58,ab,94,ac,7e,d9,98,0b,be,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002\gdq0]
"hdf12"=hex:e8,d6,a6,d1,9d,4f,23,c6,30,22,49,b1,a5,b9,bf,eb,c8,f9,9d,a9,8d,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:d8,e7,04,da,90,39,fe,8c,13,1a,01,93,d4,d0,60,a9,49,1e,16,f7,b1,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"p0"="E:\Programy\Alcohol 120\"
"h0"=dword:00000001
"ujdew"=hex:65,23,3c,f8,3f,2e,7d,9d,78,ff,c3,7f,f1,cf,fa,23,d7,50,03,8d,86,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC]
"h0"=dword:00000002
"hdf12"=hex:83,30,e9,3f,3e,63,b7,34,ab,c1,e4,f3,d4,c7,ba,90,4c,1d,50,bd,55,..
"p0"="C:\Program Files\DAEMON Tools Pro\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001]
"a0"=hex:20,01,00,00,8f,50,7e,22,8e,f9,aa,33,e3,83,fb,7f,f1,a4,88,3e,d1,..
"hdf12"=hex:87,08,d7,9a,af,0f,09,1b,4a,4d,1f,6f,e4,bb,32,ea,b7,82,d6,66,8e,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0]
"hdf12"=hex:e8,d6,a6,d1,9d,4f,23,c6,30,22,49,b1,a5,b9,bf,eb,c8,f9,9d,a9,8d,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1]
"hdf12"=hex:fa,a0,cd,09,77,3b,de,6f,ca,53,c5,2d,66,ae,a0,5d,b6,7d,2e,ff,2c,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq2]
"hdf12"=hex:e8,d6,a6,d1,9d,4f,23,c6,30,22,49,b1,a5,b9,bf,eb,c8,f9,9d,a9,8d,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq3]
"hdf12"=hex:80,fa,7a,37,de,2a,db,68,24,9f,59,22,a8,1c,5d,87,ba,91,1e,11,2e,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002]
"a0"=hex:20,01,00,00,3d,73,72,22,da,8f,60,c7,05,88,64,58,ea,21,a9,97,40,..
"hdf12"=hex:e7,49,f7,41,90,bd,95,97,09,9e,a9,2d,58,ab,94,ac,7e,d9,98,0b,be,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002\gdq0]
"hdf12"=hex:e8,d6,a6,d1,9d,4f,23,c6,30,22,49,b1,a5,b9,bf,eb,c8,f9,9d,a9,8d,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:d8,e7,04,da,90,39,fe,8c,13,1a,01,93,d4,d0,60,a9,49,1e,16,f7,b1,..
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:µTorrent"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
Remaining Files:
---------------
Files with Hidden Attributes:
Sat 12 Apr 2008 753 A.SH. --- "C:\WINDOWS\system32\mmf.sys"
Fri 22 Feb 2008 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Sat 26 Jan 2008 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Fri 30 Nov 2007 1,776 ...HR --- "C:\Documents and Settings\Administrator\Dane aplikacji\SecuROM\UserData\securom_v7_01.bak"
Finished!