- [b]SDFix: Version 1.240 [/b]
- Run by Administrator on 2010-02-09 at 21:23
- Microsoft Windows XP [Wersja 5.1.2600]
- Running From: C:\SDFix
- [b]Checking Services [/b]:
- Restoring Default Security Values
- Restoring Default Hosts File
- Rebooting
- [b]Checking Files [/b]:
- No Trojan Files Found
- Removing Temp Files
- [b]ADS Check [/b]:
- [b]Final Check [/b]:
- catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
- Rootkit scan 2010-02-09 21:26:32
- Windows 5.1.2600 Dodatek Service Pack 3 NTFS
- scanning hidden processes ...
- scanning hidden services & system hive ...
- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
- "s1"=dword:2df9c43f
- "s2"=dword:110480d0
- "h0"=dword:00000001
- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC]
- "h0"=dword:00000000
- "hdf12"=hex:0a,74,9b,ef,a5,bc,b5,13,4b,b2,1b,c7,67,b1,7c,dd,c3,2b,67,f0,24,..
- "p0"="C:\Program Files\DAEMON Tools Pro\"
- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001]
- "a0"=hex:20,01,00,00,ae,41,da,62,bd,69,ac,88,5a,2f,f8,59,8e,af,b1,e9,c0,..
- "hdf12"=hex:e4,60,2c,24,d4,81,c1,17,6c,82,a4,d4,99,5c,3f,46,af,8c,f7,31,9a,..
- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0]
- "hdf12"=hex:b6,54,c9,a6,c2,09,2c,f2,28,3f,07,c2,24,c4,34,87,98,83,80,ab,da,..
- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002]
- "a0"=hex:20,01,00,00,40,01,d8,62,11,35,1e,b6,78,75,c1,36,d5,d9,ec,fa,95,..
- "hdf12"=hex:9c,dd,32,fe,a8,db,c6,86,d3,b0,7f,d8,ee,9e,cc,22,c0,2e,04,0e,a5,..
- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002\gdq0]
- "hdf12"=hex:3a,b0,90,d3,d4,31,3f,81,12,a4,c5,9c,49,81,9f,52,8b,fc,cd,95,e4,..
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC]
- "h0"=dword:00000000
- "hdf12"=hex:0a,74,9b,ef,a5,bc,b5,13,4b,b2,1b,c7,67,b1,7c,dd,c3,2b,67,f0,24,..
- "p0"="C:\Program Files\DAEMON Tools Pro\"
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001]
- "a0"=hex:20,01,00,00,ae,41,da,62,bd,69,ac,88,5a,2f,f8,59,8e,af,b1,e9,c0,..
- "hdf12"=hex:e4,60,2c,24,d4,81,c1,17,6c,82,a4,d4,99,5c,3f,46,af,8c,f7,31,9a,..
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0]
- "hdf12"=hex:b6,54,c9,a6,c2,09,2c,f2,28,3f,07,c2,24,c4,34,87,98,83,80,ab,da,..
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002]
- "a0"=hex:20,01,00,00,40,01,d8,62,11,35,1e,b6,78,75,c1,36,d5,d9,ec,fa,95,..
- "hdf12"=hex:9c,dd,32,fe,a8,db,c6,86,d3,b0,7f,d8,ee,9e,cc,22,c0,2e,04,0e,a5,..
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002\gdq0]
- "hdf12"=hex:3a,b0,90,d3,d4,31,3f,81,12,a4,c5,9c,49,81,9f,52,8b,fc,cd,95,e4,..
- scanning hidden registry entries ...
- scanning hidden files ...
- scan completed successfully
- hidden processes: 0
- hidden services: 0
- hidden files: 0
- [b]Remaining Services [/b]:
- Authorized Application Key Export:
- [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
- "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
- "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
- "C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe:*:Disabled:Logitech Desktop Messenger"
- "C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:uTorrent"
- "D:\\Deep Silver\\S.T.A.L.K.E.R. - Clear Sky\\bin\\xrEngine.exe"="D:\\Deep Silver\\S.T.A.L.K.E.R. - Clear Sky\\bin\\xrEngine.exe:*:Enabled:S.T.A.L.K.E.R. - Clear Sky (CLI)"
- "D:\\Deep Silver\\S.T.A.L.K.E.R. - Clear Sky\\bin\\dedicated\\xrEngine.exe"="D:\\Deep Silver\\S.T.A.L.K.E.R. - Clear Sky\\bin\\dedicated\\xrEngine.exe:*:Enabled:S.T.A.L.K.E.R. - Clear Sky (SRV)"
- "C:\\WINDOWS\\system32\\rundll32.exe"="C:\\WINDOWS\\system32\\rundll32.exe:*:Enabled:Uruchamia plik DLL jako aplikacj©"
- "C:\\WINDOWS\\system32\\dpvsetup.exe"="C:\\WINDOWS\\system32\\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
- "C:\\Program Files\\Java\\jre6\\bin\\java.exe"="C:\\Program Files\\Java\\jre6\\bin\\java.exe:*:Enabled:Java(TM) Platform SE binary"
- "C:\\WINDOWS\\system32\\PnkBstrA.exe"="C:\\WINDOWS\\system32\\PnkBstrA.exe:*:Enabled:PnkBstrA"
- "C:\\WINDOWS\\system32\\PnkBstrB.exe"="C:\\WINDOWS\\system32\\PnkBstrB.exe:*:Enabled:PnkBstrB"
- "D:\\THQ\\Dawn of War - Dark Crusade\\DarkCrusade.exe"="D:\\THQ\\Dawn of War - Dark Crusade\\DarkCrusade.exe:*:Enabled:DarkCrusade"
- "C:\\Program Files\\Mozilla Firefox\\firefox.exe"="C:\\Program Files\\Mozilla Firefox\\firefox.exe:*:Enabled:Firefox"
- "C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
- "C:\\Program Files\\Nowe Gadu-Gadu\\gg.exe"="C:\\Program Files\\Nowe Gadu-Gadu\\gg.exe:*:Enabled:Nowe Gadu-Gadu"
- "D:\\Activision\\Call of Duty Modern Warfare 2\\iw4mp.exe"="D:\\Activision\\Call of Duty Modern Warfare 2\\iw4mp.exe:*:Enabled:iw4mp"
- "C:\\Program Files\\Hamachi\\hamachi.exe"="C:\\Program Files\\Hamachi\\hamachi.exe:*:Enabled:Hamachi Client"
- "C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
- [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
- "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
- "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
- "C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"
- [b]Remaining Files [/b]:
- [b]Files with Hidden Attributes [/b]:
- Tue 9 Feb 2010 102,400 ..SHR --- "C:\Documents and Settings\MiChAˆ\zaian.exe"
- Tue 21 Jul 2009 88 ..SHR --- "C:\WINDOWS\system32\5471A9B09A.sys"
- Mon 1 Feb 2010 2,568 A.SH. --- "C:\WINDOWS\system32\KGyGaAvL.sys"
- Thu 21 Jan 2010 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
- [b]Finished![/b]