SDFix: Version 1.116 Run by Mistrzu on 2007-11-28 at 23:05 Microsoft Windows XP [Version 5.1.2600] Running From: C:\SDFix Safe Mode: Checking Services: Restoring Windows Registry Values Restoring Windows Default Hosts File Rebooting… Normal Mode: Checking Files: No Trojan Files Found Removing Temp Files… ADS Check: C:\WINDOWS No streams found. C:\WINDOWS\system32 No streams found. C:\WINDOWS\system32\svchost.exe No streams found. C:\WINDOWS\system32\ntoskrnl.exe No streams found. Final Check: catchme 0.3.1262.1 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-11-28 23:16:23 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes … scanning hidden services & system hive … [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg] “s1”=dword:2df9c43f “s2”=dword:110480d0 “h0”=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04] “p0”=“C:\Program Files\Alcohol Soft\Alcohol 120” “h0”=dword:00000000 “ujdew”=hex:83,fd,96,f6,a0,27,cd,4b,45,7c,62,c6,5d,09,68,bf,96,79,5b,79,f3,… [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control] “WaitToKillServiceTimeout”=“4000” [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Session Manager\Memory Management\PrefetchParameters] “VideoInitTime”=dword:00000530 [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Watchdog\Display] “ShutdownCount”=dword:000003e0 [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\ACPI\PNPA000\4&5d18f2df&0] “Service”=“ac13aw8q” [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Epoch] “Epoch”=dword:000017e5 [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04] “p0”=“C:\Program Files\Alcohol Soft\Alcohol 120” “h0”=dword:00000000 “ujdew”=hex:83,fd,96,f6,a0,27,cd,4b,45,7c,62,c6,5d,09,68,bf,96,79,5b,79,f3,… [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SynTP\Parameters] “DetectTimeMS”=dword:000003ad [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\WmiApRpl\Performance] “Last Counter”=dword:000013b8 “Last Help”=dword:000013b9 “Object List”=“4998 4998 5004 5004 5016 5016 5024 5024 5030 5030” scanning hidden registry entries … [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Paj\x0105czek 5 NxG STD_is1] “SlowInfoCache”=hex:28,02,00,00,01,00,00,00,00,d0,6a,01,00,00,00,00,7a,c5,f8,c7,ff,… “Changed”=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib] “Last Counter”=dword:0000138a “Last Help”=dword:0000138b [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19] “RefCount”=dword:00000002 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\AidemMedia\Wersje demonstracyjne\Szko\x0142a Kozio\x142ka Mato\x142ka] “Order”=hex:08,00,00,00,02,00,00,00,be,01,00,00,01,00,00,00,03,00,00,00,7e,… scanning hidden files … scan completed successfully hidden processes: 0 hidden services: 0 hidden files: 0 Remaining Services: ------------------ Authorized Application Key Export: [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] Remaining Files: --------------- Files with Hidden Attributes: Mon 4 Jun 2007 56 …SHR — “C:\WINDOWS\system32\041CF54FA8.sys” Mon 25 Jun 2007 88 …SHR — “C:\WINDOWS\system32\A84FF51C04.sys” Mon 25 Jun 2007 3,766 A.SH. — “C:\WINDOWS\system32\KGyGaAvL.sys” Mon 15 Oct 2007 165,232 A…H. — “C:\Documents and Settings\Mistrzu\Application Data\Microsoft\Virtual PC\VPCKeyboard.dll” Finished!