co do tego host process for win 32, to nie mam takiego błędu.
nie robilem, bo mam Kasperskyego, nim zrobilem skanowanie, i nic mi nie wykrył.
SDFix: Version 1.157
Run by Artur on 2008-03-14 at 16:21
Microsoft Windows XP [Wersja 5.1.2600]
Running From: C:\SDFix
Checking Services :
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting
Checking Files :
No Trojan Files Found
Removing Temp Files
ADS Check :
Final Check :
catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-14 16:24:30
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="F:\DAEMON Tools\"
"h0"=dword:00000000
"khjeh"=hex:96,bd,06,ae,dd,42,bc,7b,6a,e4,20,81,ce,5a,78,ed,1d,9a,ff,b6,d2,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,ad,f7,07,a1,fa,1f,0f,32,25,fb,6e,82,3b,9d,5a,ef,d3,..
"khjeh"=hex:3f,4e,9b,da,7c,cd,37,9a,e4,91,84,14,fa,a3,0e,5a,56,77,32,90,ff,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:d3,6e,1a,08,fe,0b,94,d1,7b,d1,d7,a2,91,9b,2f,3d,09,c8,5d,6b,a7,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="F:\DAEMON Tools\"
"h0"=dword:00000000
"khjeh"=hex:96,bd,06,ae,dd,42,bc,7b,6a,e4,20,81,ce,5a,78,ed,1d,9a,ff,b6,d2,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,ad,f7,07,a1,fa,1f,0f,32,25,fb,6e,82,3b,9d,5a,ef,d3,..
"khjeh"=hex:3f,4e,9b,da,7c,cd,37,9a,e4,91,84,14,fa,a3,0e,5a,56,77,32,90,ff,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:d3,6e,1a,08,fe,0b,94,d1,7b,d1,d7,a2,91,9b,2f,3d,09,c8,5d,6b,a7,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s0"=dword:fb1ec042
"s1"=dword:731b201c
"s2"=dword:de1781ff
"h0"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="F:\DAEMON Tools\"
"h0"=dword:00000000
"khjeh"=hex:96,bd,06,ae,dd,42,bc,7b,6a,e4,20,81,ce,5a,78,ed,1d,9a,ff,b6,d2,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,ad,f7,07,a1,fa,1f,0f,32,25,fb,6e,82,3b,9d,5a,ef,d3,..
"khjeh"=hex:3f,4e,9b,da,7c,cd,37,9a,e4,91,84,14,fa,a3,0e,5a,56,77,32,90,ff,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:98,af,73,08,23,10,2a,b6,ed,70,a8,83,50,de,cf,71,70,69,18,44,52,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41]
"khjeh"=hex:ee,4b,5e,6b,c4,10,c1,ce,79,67,54,fb,cb,5d,ad,9a,d4,bc,b3,3f,f1,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42]
"khjeh"=hex:0d,70,95,89,bc,14,b0,2c,83,33,7b,a4,aa,67,a8,d0,36,21,65,ae,1a,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="F:\DAEMON Tools\"
"h0"=dword:00000000
"khjeh"=hex:96,bd,06,ae,dd,42,bc,7b,6a,e4,20,81,ce,5a,78,ed,1d,9a,ff,b6,d2,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,ad,f7,07,a1,fa,1f,0f,32,25,fb,6e,82,3b,9d,5a,ef,d3,..
"khjeh"=hex:3f,4e,9b,da,7c,cd,37,9a,e4,91,84,14,fa,a3,0e,5a,56,77,32,90,ff,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:98,af,73,08,23,10,2a,b6,ed,70,a8,83,50,de,cf,71,70,69,18,44,52,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41]
"khjeh"=hex:ee,4b,5e,6b,c4,10,c1,ce,79,67,54,fb,cb,5d,ad,9a,d4,bc,b3,3f,f1,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42]
"khjeh"=hex:0d,70,95,89,bc,14,b0,2c,83,33,7b,a4,aa,67,a8,d0,36,21,65,ae,1a,..
scanning hidden registry entries ...
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\A\1\5\1c]
"Order"=hex:08,00,00,00,02,00,00,00,b8,01,00,00,01,00,00,00,04,00,00,00,8c,..
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:uTorrent"
"E:\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"="E:\\Call of Duty 4 - Modern Warfare\\iw3mp.exe:*:Enabled:Call of Duty(R) 4 - Modern Warfare(TM)"
"E:\\Crysis\\Bin32\\Crysis.exe"="E:\\Crysis\\Bin32\\Crysis.exe:*:Enabled:Crysis_32"
"E:\\Crysis\\Bin32\\CrysisDedicatedServer.exe"="E:\\Crysis\\Bin32\\CrysisDedicatedServer.exe:*:Enabled:CrysisDedicatedServer_32"
"C:\\WINDOWS\\system32\\PnkBstrA.exe"="C:\\WINDOWS\\system32\\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\\WINDOWS\\system32\\PnkBstrB.exe"="C:\\WINDOWS\\system32\\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
Remaining Files :
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes :
Wed 4 Aug 2004 1,667,584 ..SH. --- "C:\Program Files\Messenger\msmsgs.exe"
Tue 3 Aug 2004 60,928 A.SH. --- "C:\Program Files\Outlook Express\msimn.exe"
Wed 20 Feb 2008 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Sun 27 Jan 2008 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Tue 3 Aug 2004 73,728 A.SH. --- "C:\WINDOWS\RegisteredPackages\{DD90D410-1823-43EB-9A16-A2331BF08799}$BACKUP$\System\wmplayer.exe"
Finished!
I gdy wcisne dowolny klawisz, to poprostu okno się zamyka, a mam Windowsa XP...
Licze na odpowiedz, pozdrawiam.