SDFix: Version 1.114
Run by M@rcin on 2007-11-11 at 09:32
Microsoft Windows XP [Wersja 5.1.2600]
Running From: C:\SDFix\SDFix
Safe Mode:
Checking Services:
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Restoring Default HomePage Value
Restoring Default Desktop Components Value
Rebooting...
Normal Mode:
Checking Files:
Trojan Files Found:
C:\Program Files\RichVideoCodec\install.ico - Deleted
C:\Program Files\RichVideoCodec\RichVideoCodec.ocx - Deleted
C:\Program Files\RichVideoCodec\Uninstall.exe - Deleted
C:\WINDOWS\IPWYPTFG.DLL - Deleted
Folder C:\Program Files\RichVideoCodec - Removed
Removing Temp Files...
ADS Check:
C:\WINDOWS
No streams found.
C:\WINDOWS\system32
No streams found.
C:\WINDOWS\system32\svchost.exe
No streams found.
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.
Final Check:
catchme 0.3.1262.1 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-11 09:35:19
Windows 5.1.2600 Dodatek Service Pack. 1 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40]
"khjeh"=hex:20,02,00,00,16,92,2b,04,49,39,ce,1b,72,49,2c,28,b9,49,f6,85,f3,..
"hj34z0"=hex:59,15,ce,48,dd,14,3a,5c,bd,04,e1,f1,62,58,f6,29,a2,47,71,6b,9d,..
"hj34z1"=hex:c6,15,ce,48,a5,14,3a,5c,bc,04,e0,f1,63,58,f6,29,a2,47,71,6b,51,..
"hj34z2"=hex:c6,15,ce,48,a5,14,3a,5c,bc,04,e0,f1,63,58,f6,29,a2,47,71,6b,51,..
"hj34z3"=hex:c6,15,ce,48,a5,14,3a,5c,bc,04,e0,f1,63,58,f6,29,a2,47,71,6b,51,..
"hj34z4"=hex:c6,15,ce,48,a5,14,3a,5c,bc,04,e0,f1,63,58,f6,29,a2,47,71,6b,51,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf41]
"khjeh"=hex:20,02,00,00,16,92,2b,04,26,9e,57,d0,72,49,2c,28,bb,49,f6,85,f3,..
"hj34z0"=hex:5b,15,ce,48,dd,14,3a,5c,bd,04,e1,f1,62,58,f6,29,a2,47,71,6b,ef,..
"hj34z1"=hex:c6,15,ce,48,a5,14,3a,5c,bc,04,e0,f1,63,58,f6,29,a2,47,71,6b,51,..
"hj34z2"=hex:c6,15,ce,48,a5,14,3a,5c,bc,04,e0,f1,63,58,f6,29,a2,47,71,6b,51,..
"hj34z3"=hex:c6,15,ce,48,a5,14,3a,5c,bc,04,e0,f1,63,58,f6,29,a2,47,71,6b,51,..
"hj34z4"=hex:c6,15,ce,48,a5,14,3a,5c,bc,04,e0,f1,63,58,f6,29,a2,47,71,6b,51,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:2df9c43f
"s2"=dword:110480d0
"h0"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"p0"="C:\Program Files\Alcohol Soft\Alcohol 120\"
"h0"=dword:00000000
"ujdew"=hex:c1,6b,2e,01,0c,05,07,1b,0c,ba,03,c5,bc,d1,7f,c5,17,8a,8c,29,29,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"p0"="C:\Program Files\Alcohol Soft\Alcohol 120\"
"h0"=dword:00000000
"ujdew"=hex:c1,6b,2e,01,0c,05,07,1b,0c,ba,03,c5,bc,d1,7f,c5,17,8a,8c,29,29,..
scanning hidden registry entries ...
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\A\1\5\1c]
"Order"=hex:08,00,00,00,02,00,00,00,b8,01,00,00,01,00,00,00,04,00,00,00,8c,..
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
Remaining Files:
---------------
File Backups: - C:\SDFix\SDFix\backups\backups.zip
Files with Hidden Attributes:
Sat 17 Feb 2007 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Fri 29 Jun 2007 400 ..SH. --- "C:\Documents and Settings\All Users\DRM\v2ks.bla.bak"
Fri 29 Jun 2007 48 ..SH. --- "C:\Documents and Settings\All Users\DRM\v2ks.sec.bak"
Sun 26 Aug 2007 4,348 A.SH. --- "C:\Documents and Settings\All Users.WINDOWS\DRM\DRMv1.bak"
Sun 19 Aug 2007 3,858,985 A..H. --- "C:\Documents and Settings\Sylwusia\Pulpit\eMule0.48a-Installer.exe"
Finished!