SDFix: Version 1.131
Run by HOME on 2008-01-24 at 05:39
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting...
Normal Mode:
Checking Files:
Trojan Files Found:
C:\PROGRA~1\ONLINE~1\LAWUHE - Deleted
C:\Temp\1cb\syscheck.log - Deleted
Could Not Remove C:\WINDOWS\system32\drivers\core.cache.dsk
Folder C:\Temp\1cb - Removed
Folder C:\Temp\tn3 - Removed
Removing Temp Files...
ADS Check:
C:\WINDOWS
No streams found.
C:\WINDOWS\explorer.exe
No streams found.
C:\WINDOWS\system32
No streams found.
C:\WINDOWS\system32\svchost.exe
No streams found.
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.
Final Check:
catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-24 05:54:00
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\s ptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:9b,4a,54,c9,30,32,45,0c,3d,c5,83,e9,a2 ,8e,b8,1b,3d,bc,16,57,42,..
"p0"="C:\Program Files\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\s ptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"khjeh"=hex:a8,15,f3,a7,78,53,5f,2a,29,de,d2,14,63 ,73,6a,a4,46,22,c5,e0,4d,..
"a0"=hex:20,01,00,00,ba,39,7a,b3,a3,9a,de,ac,4e,ba ,e3,3e,0a,c8,d9,66,fc,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\s ptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\ 0Jf40]
"khjeh"=hex:f8,9b,02,00,75,d4,bd,dd,18,7f,79,2c,a2 ,4d,a4,86,ee,31,54,66,0d,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\s ptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:9b,4a,54,c9,30,32,45,0c,3d,c5,83,e9,a2 ,8e,b8,1b,3d,bc,16,57,42,..
"p0"="C:\Program Files\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\s ptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"khjeh"=hex:a8,15,f3,a7,78,53,5f,2a,29,de,d2,14,63 ,73,6a,a4,46,22,c5,e0,4d,..
"a0"=hex:20,01,00,00,ba,39,7a,b3,a3,9a,de,ac,4e,ba ,e3,3e,0a,c8,d9,66,fc,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\s ptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\ 0Jf40]
"khjeh"=hex:f8,9b,02,00,75,d4,bd,dd,18,7f,79,2c,a2 ,4d,a4,86,ee,31,54,66,0d,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\s ptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:9b,4a,54,c9,30,32,45,0c,3d,c5,83,e9,a2 ,8e,b8,1b,3d,bc,16,57,42,..
"p0"="C:\Program Files\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\s ptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"khjeh"=hex:a8,15,f3,a7,78,53,5f,2a,29,de,d2,14,63 ,73,6a,a4,46,22,c5,e0,4d,..
"a0"=hex:20,01,00,00,ba,39,7a,b3,a3,9a,de,ac,4e,ba ,e3,3e,0a,c8,d9,66,fc,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\s ptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\ 0Jf40]
"khjeh"=hex:f8,9b,02,00,75,d4,bd,dd,18,7f,79,2c,a2 ,4d,a4,86,ee,31,54,66,0d,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\s ptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:9b,4a,54,c9,30,32,45,0c,3d,c5,83,e9,a2 ,8e,b8,1b,3d,bc,16,57,42,..
"p0"="C:\Program Files\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\s ptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"khjeh"=hex:a8,15,f3,a7,78,53,5f,2a,29,de,d2,14,63 ,73,6a,a4,46,22,c5,e0,4d,..
"a0"=hex:20,01,00,00,ba,39,7a,b3,a3,9a,de,ac,4e,ba ,e3,3e,0a,c8,d9,66,fc,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\s ptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\ 0Jf40]
"khjeh"=hex:f8,9b,02,00,75,d4,bd,dd,18,7f,79,2c,a2 ,4d,a4,86,ee,31,54,66,0d,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet005\Services\s ptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:9b,4a,54,c9,30,32,45,0c,3d,c5,83,e9,a2 ,8e,b8,1b,3d,bc,16,57,42,..
"p0"="C:\Program Files\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet005\Services\s ptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"khjeh"=hex:a8,15,f3,a7,78,53,5f,2a,29,de,d2,14,63 ,73,6a,a4,46,22,c5,e0,4d,..
"a0"=hex:20,01,00,00,ba,39,7a,b3,a3,9a,de,ac,4e,ba ,e3,3e,0a,c8,d9,66,fc,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet005\Services\s ptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\ 0Jf40]
"khjeh"=hex:f8,9b,02,00,75,d4,bd,dd,18,7f,79,2c,a2 ,4d,a4,86,ee,31,54,66,0d,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\sptd\Cfg]
"s1"=dword:454d47db
"s2"=dword:6b88637f
"h0"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:3c,1b,7d,3e,ee,f6,1b,46,eb,9f,db,ac,e1 ,b9,5a,95,fa,53,fc,84,44,..
"p0"="C:\Program Files\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000 001]
"khjeh"=hex:a8,15,f3,a7,78,53,5f,2a,29,de,d2,14,63 ,73,6a,a4,46,22,c5,e0,4d,..
"a0"=hex:20,01,00,00,ba,39,7a,b3,a3,9a,de,ac,4e,ba ,e3,3e,0a,c8,d9,66,fc,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000 001\0Jf40]
"khjeh"=hex:56,9f,0c,15,f7,fc,d2,02,83,2a,43,88,28 ,8c,89,82,f7,a2,cf,02,94,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet007\Services\s ptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:3c,1b,7d,3e,ee,f6,1b,46,eb,9f,db,ac,e1 ,b9,5a,95,fa,53,fc,84,44,..
"p0"="C:\Program Files\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet007\Services\s ptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"khjeh"=hex:a8,15,f3,a7,78,53,5f,2a,29,de,d2,14,63 ,73,6a,a4,46,22,c5,e0,4d,..
"a0"=hex:20,01,00,00,ba,39,7a,b3,a3,9a,de,ac,4e,ba ,e3,3e,0a,c8,d9,66,fc,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet007\Services\s ptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\ 0Jf40]
"khjeh"=hex:56,9f,0c,15,f7,fc,d2,02,83,2a,43,88,28 ,8c,89,82,f7,a2,cf,02,94,..
scanning hidden registry entries ...
[HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Shell Extensions\Approved\{7F2A5A8B-FF2E-2DEC-FD9A-5DD9B2E85420}]
"kaekikhkmnmnpffpgddjdm"=hex:67,61,65,6b,6d,6b,6c, 6e,6b,65,66,6d,64,6c,00,00
"kaekikhkmnmnpffpgddjam"=hex:66,61,65,70,6c,6d,69, 6a,69,63,68,6c,00,70
"maenlfgcdbmlmepomdfbahhcfe"=hex:62,61,68,6a,0 0,fa
scanning hidden files ...
C:\WINDOWS\SoftwareDistribution\DataStore\Logs\tmp .edb
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 1
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\sharedaccess\parameters\firewallpolicy\standard profile\authorizedapplications\list]
"C:\\Program Files\\utorrent\\utorrent.exe"="C:\\Program Files\\utorrent\\utorrent.exe:*:Enabled:µTorrent"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader"
"C:\\Documents and Settings\\HOME\\Desktop\\utorrent.exe"="C:\\Docume nts and Settings\\HOME\\Desktop\\utorrent.exe:*:Enabled:µT orrent"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"="C:\\Program Files\\Grisoft\\AVG7\\avginet.exe:*:Enabled:avgine t.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe:*:Enabled:avgam svr.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe:*:Enabled:avgcc.ex e"
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe:*:Enabled:avgemc. exe"
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\ \Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Ena bled:Yahoo! Messenger"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Messenger"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\sharedaccess\parameters\firewallpolicy\domainpr ofile\authorizedapplications\list]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
Remaining Files:
---------------
C:\WINDOWS\system32\drivers\core.cache.dsk Found
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes:
Sat 28 Jul 2007 1,772,766 A.SH. --- "C:\WINDOWS\system32\qqstv.tmp"
Sat 24 Feb 2007 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Sat 24 Mar 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Sun 23 Dec 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\0a67b6c4 06b1d7e0f5c1e6f6d44a3f6e\BIT32.tmp"
Sun 23 Dec 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\26924cbc 8132a10b438ce6e2b49d4652\BIT30.tmp"
Sun 23 Dec 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\2769b111 678c52099a3b3123b12f2325\BIT34.tmp"
Sun 23 Dec 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\b69c46c5 109d0f8b0dee9fab84906813\BIT33.tmp"
Sun 23 Dec 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\d77b9b5b 8fed23dd91f50d167cce60d3\BIT35.tmp"
Sun 23 Dec 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\fa6c916b b150f8a929e7a4ffdfbc120f\BIT31.tmp"
Sat 12 Jan 2008 444 ...HR --- "C:\Documents and Settings\HOME\Application Data\SecuROM\UserData\securom_v7_01.bak"
Sat 24 Feb 2007 4,348 ...H. --- "C:\Documents and Settings\HOME\My Documents\My Music\License Backup\drmv1key.bak"
Mon 31 Dec 2007 20 A..H. --- "C:\Documents and Settings\HOME\My Documents\My Music\License Backup\drmv1lic.bak"
Thu 17 May 2007 11,754 A.SH. --- "C:\Documents and Settings\HOME\My Documents\My Music\License Backup\drmv2key.bak"
Finished!