********************************* ROOTCHK-(22-08-07)-LOG, by ejvindh
11-09-2007 13:01:24,59
Driver npf (visible) is present. Run COMBOFIX by sUBs.
********************************* ROOTCHK-LOG-end
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2007-09-11 13:01:25
Windows 5.1.2600 Service Pack 2
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:90,f2,b1,ff,c8,73,e4,0a,62,64,6d,71,21,7e,b5,9a,9b,20,6b,82,11,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000001
"khjeh"=hex:09,88,f8,fd,d2,20,32,d5,76,5a,53,02,a6,8c,f3,fa,07,97,7b,e9,0b,..
"p0"="C:\Programmer\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
]
"khjeh"=hex:ad,c5,6b,4b,86,6b,fb,d8,d0,47,b1,ea,0f,09,15,b3,55,31,d0,ab,c9,..
"a0"=hex:20,01,00,00,72,8d,57,03,cb,65,6a,f5,c6,f0,6f,03,72,39,d1,71,c4,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
\0Jf40]
"khjeh"=hex:17,02,5f,a3,1f,28,03,56,d2,24,e8,0f,5c,4b,87,82,21,d2,a0,af,9a,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
\0Jf41]
"khjeh"=hex:86,b5,02,ff,1b,97,5e,96,89,7c,55,31,66,5e,29,86,20,2e,fd,ca,a3,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:71f61582
"s2"=dword:38a6194d
"h0"=dword:00000002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:90,f2,b1,ff,c8,73,e4,0a,62,64,6d,71,21,7e,b5,9a,9b,20,6b,82,11,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000001
"khjeh"=hex:23,11,63,65,2b,24,ae,a1,de,a2,c4,96,84,34,55,7b,f3,a4,e6,b7,1e,..
"p0"="C:\Programmer\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\0000
0001]
"khjeh"=hex:ad,a9,1e,51,d0,8a,a0,f9,03,e0,37,4e,db,79,cc,b8,1b,8c,66,d7,99,..
"a0"=hex:20,01,00,00,72,8d,57,03,cb,65,6a,f5,c6,f0,6f,03,72,39,d1,71,c4,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\0000
0001\0Jf40]
"khjeh"=hex:89,ee,0f,d3,67,91,e9,0b,1f,91,76,11,96,b9,1b,69,76,cf,c2,cd,f5,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\0000
0001\0Jf41]
"khjeh"=hex:86,b5,02,ff,1b,97,5e,96,89,7c,55,31,66,5e,29,86,20,2e,fd,ca,a3,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:90,f2,b1,ff,c8,73,e4,0a,62,64,6d,71,21,7e,b5,9a,9b,20,6b,82,11,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000001
"khjeh"=hex:23,11,63,65,2b,24,ae,a1,de,a2,c4,96,84,34,55,7b,f3,a4,e6,b7,1e,..
"p0"="C:\Programmer\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
]
"khjeh"=hex:ad,a9,1e,51,d0,8a,a0,f9,03,e0,37,4e,db,79,cc,b8,1b,8c,66,d7,99,..
"a0"=hex:20,01,00,00,72,8d,57,03,cb,65,6a,f5,c6,f0,6f,03,72,39,d1,71,c4,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
\0Jf40]
"khjeh"=hex:89,ee,0f,d3,67,91,e9,0b,1f,91,76,11,96,b9,1b,69,76,cf,c2,cd,f5,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
\0Jf41]
"khjeh"=hex:86,b5,02,ff,1b,97,5e,96,89,7c,55,31,66,5e,29,86,20,2e,fd,ca,a3,..
scanning hidden registry entries ...
scanning hidden files ...
hidden processes: 0
hidden files: 0