catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-29 01:50:00
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden services & system hive ...

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40]
"khjeh"=hex:20,02,00,00,10,87,a1,ce,b8,5d,2e,33,f8,df,d5,4f,49,94,ee,fb,68,..
"hj34z0"=hex:d9,26,e5,c7,47,83,c3,3b,7f,c8,f9,8f,fc,f5,68,1a,34,bc,35,ce,38,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf41]
"khjeh"=hex:20,02,00,00,10,87,a1,ce,ef,b1,8c,34,f8,df,d5,4f,d2,94,ee,fb,6e,..
"hj34z0"=hex:42,26,e5,c7,47,83,c3,3b,7f,c8,f9,8f,fc,f5,68,1a,34,bc,35,ce,4d,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:2df9c43f
"s2"=dword:110480d0
"h0"=dword:00000001

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:c7,d3,41,a9,51,b3,62,bf,d6,19,f6,a9,29,28,ea,c5,ed,3e,e1,28,73,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:c7,d3,41,a9,51,b3,62,bf,d6,19,f6,a9,29,28,ea,c5,ed,3e,e1,28,73,..

scanning hidden registry entries ...

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\\24\xe1\21]
"DisplayName"="\x1768\x22f\x1768\x22f\1"
"DeviceDesc"="\x1768\x22f\x1768\x22f\1"
"ProviderName"="\xfed4\21\xee18\x7c91\xff44\21\b"
"MFG"="\x5b8"
"ReinstallString"="C:\WINDOWS\System32\ReinstallBackups\\xe114\21\x80\xc010\DriverFiles\.INF"
"DeviceInstanceIds"=str(7):"c:\docume~1\propie~1\config~1\temp\pftcd.tmp\source\sbdrv\smbus\smbusati.inf"

scanning hidden files ...


scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 71

