SDFix: Version 1.117 Run by DOM on 2008-04-06 at 18:54 Microsoft Windows XP [Wersja 5.1.2600] Running From: C:\SDFix Safe Mode: Checking Services: Name: FCI Path: C:\WINDOWS\system32\svchost.exe:ext.exe FCI - Deleted Restoring Windows Registry Values Restoring Windows Default Hosts File Rebooting… Normal Mode: Checking Files: Trojan Files Found: C:\DOCUME~1\DOM\USTAWI~1\Temp\winlogon.exe - Deleted Removing Temp Files… ADS Check: C:\WINDOWS No streams found. C:\WINDOWS\system32 No streams found. C:\WINDOWS\system32\svchost.exe No streams found. C:\WINDOWS\system32\ntoskrnl.exe No streams found. Final Check: catchme 0.3.1262.1 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-04-06 18:58:53 Windows 5.1.2600 Dodatek Service Pack 2 NTFS scanning hidden processes … IPC error: 2 Nie można odnaleźć określonego pliku. scanning hidden services & system hive … [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4] “h0”=dword:00000000 “khjeh”=hex:a2,56,d2,f7,c0,37,72,47,25,f8,49,19,32,d5,a6,c3,fc,1c,89,19,bf,… “p0”=“C:\Program Files\DAEMON Tools” [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001] “khjeh”=hex:4d,8c,99,45,a2,34,27,90,46,f2,f4,3c,a3,f1,85,5b,47,f0,53,fa,44,… “a0”=hex:20,01,00,00,28,07,e6,f1,49,b7,0d,51,a0,38,26,b0,cc,0e,7e,bf,2e,… [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40] “khjeh”=hex:92,86,26,00,4e,5a,26,ce,e2,84,83,14,16,3c,48,57,ee,e5,e8,86,4e,… [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41] “khjeh”=hex:02,02,86,88,c9,1e,9a,7f,3e,01,12,94,de,67,34,96,f9,51,07,cb,22,… [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4] “h0”=dword:00000000 “khjeh”=hex:a2,56,d2,f7,c0,37,72,47,25,f8,49,19,32,d5,a6,c3,fc,1c,89,19,bf,… “p0”=“C:\Program Files\DAEMON Tools” [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001] “khjeh”=hex:4d,8c,99,45,a2,34,27,90,46,f2,f4,3c,a3,f1,85,5b,47,f0,53,fa,44,… “a0”=hex:20,01,00,00,28,07,e6,f1,49,b7,0d,51,a0,38,26,b0,cc,0e,7e,bf,2e,… [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40] “khjeh”=hex:92,86,26,00,4e,5a,26,ce,e2,84,83,14,16,3c,48,57,ee,e5,e8,86,4e,… [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41] “khjeh”=hex:02,02,86,88,c9,1e,9a,7f,3e,01,12,94,de,67,34,96,f9,51,07,cb,22,… [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg] “s1”=dword:d1bb7e86 “s2”=dword:09fc6887 “h0”=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4] “h0”=dword:00000000 “khjeh”=hex:64,84,80,83,9d,c5,c4,78,d9,3d,67,4a,9c,a4,4b,29,81,5a,db,2e,48,… “p0”=“C:\Program Files\DAEMON Tools” [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001] “khjeh”=hex:4d,8c,99,45,a2,34,27,90,46,f2,f4,3c,a3,f1,85,5b,47,f0,53,fa,44,… “a0”=hex:20,01,00,00,0d,c5,af,25,ca,1a,de,d6,55,ff,23,21,db,c9,46,00,73,… [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40] “khjeh”=hex:24,5c,c8,a9,56,b8,a8,98,89,cc,35,0e,47,f8,f5,6b,40,f4,2f,ee,d5,… [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41] “khjeh”=hex:02,02,86,88,c9,1e,9a,7f,3e,01,12,94,de,67,34,96,f9,51,07,cb,22,… [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4] “h0”=dword:00000000 “khjeh”=hex:64,84,80,83,9d,c5,c4,78,d9,3d,67,4a,9c,a4,4b,29,81,5a,db,2e,48,… “p0”=“C:\Program Files\DAEMON Tools” [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001] “khjeh”=hex:4d,8c,99,45,a2,34,27,90,46,f2,f4,3c,a3,f1,85,5b,47,f0,53,fa,44,… “a0”=hex:20,01,00,00,0d,c5,af,25,ca,1a,de,d6,55,ff,23,21,db,c9,46,00,73,… [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40] “khjeh”=hex:24,5c,c8,a9,56,b8,a8,98,89,cc,35,0e,47,f8,f5,6b,40,f4,2f,ee,d5,… [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41] “khjeh”=hex:02,02,86,88,c9,1e,9a,7f,3e,01,12,94,de,67,34,96,f9,51,07,cb,22,… scanning hidden registry entries … [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\A\1\5\1c] “Order”=hex:08,00,00,00,02,00,00,00,b8,01,00,00,01,00,00,00,04,00,00,00,8c,… [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Ksi\x105\x17cka telefoniczna tel\Z\1l] “Order”=hex:08,00,00,00,02,00,00,00,40,01,00,00,01,00,00,00,02,00,00,00,b2,… scanning hidden files … scan completed successfully hidden processes: 0 hidden services: 0 hidden files: 6 Remaining Services: ------------------ Authorized Application Key Export: [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] “%windir%\system32\sessmgr.exe”="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] “%windir%\system32\sessmgr.exe”="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" Remaining Files: --------------- File Backups: - C:\SDFix\backups\backups.zip Files with Hidden Attributes: Fri 5 May 2006 56 …SHR — “C:\WINDOWS\system32\B8284344F8.sys” Thu 15 Sep 2005 110,592 A…H. — “C:\ATI\SUPPORT\5-10_xp-2k_dd_cp_wdm_27256\AtiCimUn.exe” Thu 15 Sep 2005 73,728 A…H. — “C:\ATI\SUPPORT\5-10_xp-2k_dd_cp_wdm_27256\CheckVer.exe” Thu 15 Sep 2005 154,624 A…H. — “C:\ATI\SUPPORT\5-10_xp-2k_dd_cp_wdm_27256\DrvUI64A.exe” Thu 15 Sep 2005 127,488 A…H. — “C:\ATI\SUPPORT\5-10_xp-2k_dd_cp_wdm_27256\issetup.exe” Mon 26 Jan 2004 127,488 A…H. — “C:\ATI\SUPPORT\5-10_xp-2k_dd_cp_wdm_27256\makensisw.exe” Thu 15 Sep 2005 18,192 A…H. — “C:\ATI\SUPPORT\5-10_xp-2k_dd_cp_wdm_27256\psapi.dll” Thu 15 Sep 2005 65,536 A…H. — “C:\ATI\SUPPORT\5-10_xp-2k_dd_cp_wdm_27256\Setup.exe” Mon 20 Oct 2003 73,688 …SHR — “C:\Program Files\Autodesk\Autodesk DWF Viewer\Setup.exe” Sun 25 Jan 2004 5,120 A.SHR — “C:\Program Files\Autodesk\Autodesk DWF Viewer_Setupx.dll” Thu 23 Jan 2003 65,952 …SHR — “C:\Program Files\Autodesk\Autodesk Express Viewer\Setup.exe” Thu 15 Sep 2005 6,656 A…H. — “C:\ATI\SUPPORT\5-10_xp-2k_dd_cp_wdm_27256\BIN\aticd64a.sys” Thu 15 Sep 2005 368,640 A…H. — “C:\ATI\SUPPORT\5-10_xp-2k_dd_cp_wdm_27256\BIN\aticds10.dll” Thu 15 Sep 2005 49,152 A…H. — “C:\ATI\SUPPORT\5-10_xp-2k_dd_cp_wdm_27256\BIN\AtiCIM.dll” Thu 15 Sep 2005 380,928 A…H. — “C:\ATI\SUPPORT\5-10_xp-2k_dd_cp_wdm_27256\BIN\atiicdxx.dll” Thu 15 Sep 2005 279,040 A…H. — “C:\ATI\SUPPORT\5-10_xp-2k_dd_cp_wdm_27256\BIN\atiicdxx.exe” Thu 15 Sep 2005 6,144 A…H. — “C:\ATI\SUPPORT\5-10_xp-2k_dd_cp_wdm_27256\BIN\atiicdxx.sys” Thu 15 Sep 2005 121,344 A…H. — “C:\ATI\SUPPORT\5-10_xp-2k_dd_cp_wdm_27256\BIN\EnumDev.exe” Thu 15 Sep 2005 125,440 A…H. — “C:\ATI\SUPPORT\5-10_xp-2k_dd_cp_wdm_27256\BIN\UpdatPnP.exe” Wed 5 Oct 2005 3,229 A…H. — “C:\ATI\SUPPORT\5-10_xp-2k_dd_cp_wdm_27256\CPanel\27256_XP.REG” Thu 15 Sep 2005 94,208 A…H. — “C:\ATI\SUPPORT\5-10_xp-2k_dd_cp_wdm_27256\CPanel\CPANEL.dll” Wed 5 Oct 2005 3,229 A…H. — “C:\ATI\SUPPORT\5-10_xp-2k_dd_cp_wdm_27256\CPanel\CP_XP.REG” Thu 15 Sep 2005 7,239 A…H. — “C:\ATI\SUPPORT\5-10_xp-2k_dd_cp_wdm_27256\CPanel\FGL_32.REG” Thu 15 Sep 2005 46,080 A…H. — “C:\ATI\SUPPORT\5-10_xp-2k_dd_cp_wdm_27256\CPanel\Setup.exe” Thu 15 Sep 2005 94,208 A…H. — “C:\ATI\SUPPORT\5-10_xp-2k_dd_cp_wdm_27256\Driver\Driver.DLL” Thu 15 Sep 2005 46,080 A…H. — “C:\ATI\SUPPORT\5-10_xp-2k_dd_cp_wdm_27256\Driver\Setup.exe” Fri 18 Feb 2005 139,264 A…H. — “C:\ATI\SUPPORT\5-10_xp-2k_dd_cp_wdm_27256\WDM_ALL\Setup.exe” Thu 15 Sep 2005 94,208 A…H. — “C:\ATI\SUPPORT\5-10_xp-2k_dd_cp_wdm_27256\WDM_ALL\WDM_ALL.dll” Fri 18 Jan 2008 3,046 …HR — “C:\Documents and Settings\DOM\Dane aplikacji\SecuROM\UserData\securom_v7_01.bak” Thu 15 Sep 2005 307,200 A…H. — “C:\ATI\SUPPORT\5-10_xp-2k_dd_cp_wdm_27256\Driver\2KXP_INF\B_27132\atiiiexx.dll” Thu 15 Sep 2005 57,856 A…H. — “C:\ATI\SUPPORT\5-10_xp-2k_dd_cp_wdm_27256\WDM_ALL\WDM_NSP\XP\atinbtxx.SYS” Thu 15 Sep 2005 75,776 A…H. — “C:\ATI\SUPPORT\5-10_xp-2k_dd_cp_wdm_27256\WDM_ALL\WDM_NSP\XP\atinesxx.SYS” Thu 15 Sep 2005 58,880 A…H. — “C:\ATI\SUPPORT\5-10_xp-2k_dd_cp_wdm_27256\WDM_ALL\WDM_NSP\XP\atineuxx.SYS” Thu 15 Sep 2005 166,400 A…H. — “C:\ATI\SUPPORT\5-10_xp-2k_dd_cp_wdm_27256\WDM_ALL\WDM_NSP\XP\atinevxx.SYS” Thu 15 Sep 2005 15,360 A…H. — “C:\ATI\SUPPORT\5-10_xp-2k_dd_cp_wdm_27256\WDM_ALL\WDM_NSP\XP\atinmdxx.SYS” Thu 15 Sep 2005 14,848 A…H. — “C:\ATI\SUPPORT\5-10_xp-2k_dd_cp_wdm_27256\WDM_ALL\WDM_NSP\XP\atinpdxx.SYS” Thu 15 Sep 2005 55,808 A…H. — “C:\ATI\SUPPORT\5-10_xp-2k_dd_cp_wdm_27256\WDM_ALL\WDM_NSP\XP\atinraxx.SYS” Thu 15 Sep 2005 28,672 A…H. — “C:\ATI\SUPPORT\5-10_xp-2k_dd_cp_wdm_27256\WDM_ALL\WDM_NSP\XP\atinsnxx.SYS” Thu 15 Sep 2005 13,824 A…H. — “C:\ATI\SUPPORT\5-10_xp-2k_dd_cp_wdm_27256\WDM_ALL\WDM_NSP\XP\atinttxx.SYS” Thu 15 Sep 2005 31,744 A…H. — “C:\ATI\SUPPORT\5-10_xp-2k_dd_cp_wdm_27256\WDM_ALL\WDM_NSP\XP\atinxbxx.SYS” Thu 15 Sep 2005 33,280 A…H. — “C:\ATI\SUPPORT\5-10_xp-2k_dd_cp_wdm_27256\WDM_ALL\WDM_NSP\XP\ativtmxx.DLL” Wed 4 Aug 2004 57,856 A…H. — “C:\ATI\SUPPORT\5-10_xp-2k_dd_cp_wdm_27256\WDM_ALL\WDM_SP\XP\atinbtxx.SYS” Wed 4 Aug 2004 13,824 A…H. — “C:\ATI\SUPPORT\5-10_xp-2k_dd_cp_wdm_27256\WDM_ALL\WDM_SP\XP\atinmdxx.SYS” Wed 4 Aug 2004 13,824 A…H. — “C:\ATI\SUPPORT\5-10_xp-2k_dd_cp_wdm_27256\WDM_ALL\WDM_SP\XP\atinpdxx.SYS” Wed 4 Aug 2004 53,760 A…H. — “C:\ATI\SUPPORT\5-10_xp-2k_dd_cp_wdm_27256\WDM_ALL\WDM_SP\XP\atinraxx.SYS” Wed 4 Aug 2004 105,984 A…H. — “C:\ATI\SUPPORT\5-10_xp-2k_dd_cp_wdm_27256\WDM_ALL\WDM_SP\XP\atinrvxx.SYS” Wed 4 Aug 2004 28,672 A…H. — “C:\ATI\SUPPORT\5-10_xp-2k_dd_cp_wdm_27256\WDM_ALL\WDM_SP\XP\atinsnxx.SYS” Wed 4 Aug 2004 13,824 A…H. — “C:\ATI\SUPPORT\5-10_xp-2k_dd_cp_wdm_27256\WDM_ALL\WDM_SP\XP\atinttxx.SYS” Wed 4 Aug 2004 78,336 A…H. — “C:\ATI\SUPPORT\5-10_xp-2k_dd_cp_wdm_27256\WDM_ALL\WDM_SP\XP\atintuxx.SYS” Wed 4 Aug 2004 31,744 A…H. — “C:\ATI\SUPPORT\5-10_xp-2k_dd_cp_wdm_27256\WDM_ALL\WDM_SP\XP\atinxbxx.SYS” Wed 4 Aug 2004 64,512 A…H. — “C:\ATI\SUPPORT\5-10_xp-2k_dd_cp_wdm_27256\WDM_ALL\WDM_SP\XP\atinxsxx.SYS” Wed 4 Aug 2004 32,768 A…H. — “C:\ATI\SUPPORT\5-10_xp-2k_dd_cp_wdm_27256\WDM_ALL\WDM_SP\XP\ativtmxx.DLL” Finished!