SDFix: Version 1.116
Run by Administrator on 2007-12-01 at 19:20
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Restoring Missing SharedAccess Service
Rebooting...
Normal Mode:
Checking Files:
No Trojan Files Found
Removing Temp Files...
ADS Check:
C:\WINDOWS
No streams found.
C:\WINDOWS\system32
No streams found.
C:\WINDOWS\system32\svchost.exe
No streams found.
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.
Final Check:
catchme 0.3.1262.1 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-12-01 20:00:35
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\sptd\Cfg]
"s1"=dword:2df9c43f
"s2"=dword:110480d0
"h0"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="C:\Program Files\DAEMON Tools\"
"h0"=dword:00000000
"khjeh"=hex:9a,eb,b2,f6,89,00,3c,b0,5f,d8,e8,7d,ee ,6d,e0,26,47,a9,01,65,79,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000 001]
"a0"=hex:20,01,00,00,13,f3,99,95,b8,45,72,f8,cf,b3 ,55,3f,25,5c,d5,b3,95,..
"khjeh"=hex:a8,37,6d,0e,48,6c,a8,42,62,5a,9c,60,27 ,0c,62,41,d8,24,b9,94,44,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000 001\0Jf40]
"khjeh"=hex:9b,a1,ab,c1,72,5a,00,96,bf,26,25,01,36 ,5a,4b,92,18,e8,8f,ae,dd,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\s ptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="C:\Program Files\DAEMON Tools\"
"h0"=dword:00000000
"khjeh"=hex:9a,eb,b2,f6,89,00,3c,b0,5f,d8,e8,7d,ee ,6d,e0,26,47,a9,01,65,79,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\s ptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,13,f3,99,95,b8,45,72,f8,cf,b3 ,55,3f,25,5c,d5,b3,95,..
"khjeh"=hex:a8,37,6d,0e,48,6c,a8,42,62,5a,9c,60,27 ,0c,62,41,d8,24,b9,94,44,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\s ptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\ 0Jf40]
"khjeh"=hex:9b,a1,ab,c1,72,5a,00,96,bf,26,25,01,36 ,5a,4b,92,18,e8,8f,ae,dd,..
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Reinstall\p\5\x2018|\xff\xff\xff\xff]
"DisplayName"="\x52a0\37\1"
"DeviceDesc"="\x52a0\37\1"
"ProviderName"="\x6a26\23\x945\x7c91\x94e\x7c91\xa fac"
"MFG"="\x5944\23\xec84\x7792\xec91\x7792"
"ReinstallString"="2002, 6.13.10.6129"
"DeviceInstanceIds"=str(7):""
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 3799
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\sharedaccess\parameters\firewallpolicy\standard profile\authorizedapplications\list]
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjou r"
"C:\\Program Files\\webui_v0.310_beta_2\\utorrent-1.6.1-beta-build-483.exe"="C:\\Program Files\\webui_v0.310_beta_2\\utorrent-1.6.1-beta-build-483.exe:*:Enabled:æTorrent"
"C:\\WINDOWS\\system32\\enrixhjx.exe"="C:\\WINDOWS \\system32\\enr"
"%windir%\\system32\\sessmgr.exe"="%windir%\\syste m32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\sharedaccess\parameters\firewallpolicy\domainpr ofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\syste m32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
Remaining Files:
---------------
Files with Hidden Attributes:
Fri 30 Nov 2007 20,812 ..SH. --- "C:\WINDOWS\system32\jakcrqer.dllbox"
Fri 30 Nov 2007 457,964 ..SH. --- "C:\WINDOWS\system32\jmoqr.bak2"
Mon 26 Nov 2007 456,631 ..SH. --- "C:\WINDOWS\system32\jmoqr.bak1"
Sun 18 Feb 2007 848 A.SH. --- "C:\WINDOWS\system32\KGyGaAvL.sys"
Sat 3 Mar 2007 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Sat 26 May 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp"
Fri 30 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Browns Fan\Local Settings\Temp\ico1.tmp"
Fri 30 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Browns Fan\Local Settings\Temp\ico2.tmp"
Fri 30 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Browns Fan\Local Settings\Temp\ico3.tmp"
Fri 30 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Browns Fan\Local Settings\Temp\ico4.tmp"
Fri 30 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Browns Fan\Local Settings\Temp\ico5.tmp"
Fri 30 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Browns Fan\Local Settings\Temp\ico8D.tmp"
Fri 30 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Browns Fan\Local Settings\Temp\ico8E.tmp"
Fri 30 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Browns Fan\Local Settings\Temp\ico8F.tmp"
Fri 30 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Browns Fan\Local Settings\Temp\ico90.tmp"
Fri 30 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Browns Fan\Local Settings\Temp\ico91.tmp"
Fri 30 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Browns Fan\Local Settings\Temp\ico9C.tmp"
Fri 30 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Browns Fan\Local Settings\Temp\ico9D.tmp"
Fri 30 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Browns Fan\Local Settings\Temp\ico9E.tmp"
Fri 30 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Browns Fan\Local Settings\Temp\ico9F.tmp"
Fri 30 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Browns Fan\Local Settings\Temp\icoA0.tmp"
Fri 30 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Browns Fan\Local Settings\Temp\icoA1.tmp"
Fri 30 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Browns Fan\Local Settings\Temp\icoA2.tmp"
Fri 30 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Browns Fan\Local Settings\Temp\icoA3.tmp"
Fri 30 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Browns Fan\Local Settings\Temp\icoA4.tmp"
Fri 30 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Browns Fan\Local Settings\Temp\icoA5.tmp"
Fri 30 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Browns Fan\Local Settings\Temp\icoA6.tmp"
Fri 30 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Browns Fan\Local Settings\Temp\icoA7.tmp"
Fri 30 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Browns Fan\Local Settings\Temp\icoA8.tmp"
Fri 30 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Browns Fan\Local Settings\Temp\icoA9.tmp"
Fri 30 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Browns Fan\Local Settings\Temp\icoAA.tmp"
Fri 30 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Browns Fan\Local Settings\Temp\icoAB.tmp"
Fri 30 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Browns Fan\Local Settings\Temp\icoAC.tmp"
Fri 30 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Browns Fan\Local Settings\Temp\icoAD.tmp"
Fri 30 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Browns Fan\Local Settings\Temp\icoAE.tmp"
Fri 30 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Browns Fan\Local Settings\Temp\icoAF.tmp"
Mon 13 Nov 2006 319,456 A..H. --- "C:\Program Files\Common Files\Motorola Shared\MotPCSDrivers\difxapi.dll"
Wed 19 Sep 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\cf7ced0e 70c80a1e476f1abf49afecb1\BIT3.tmp"
Finished!