SDFix: Version 1.114
Run by Andrew Taylor on Thu 11/15/2007 at 09:33 AM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Safe Mode: Checking Services:
Name: aspimgr
Path: C:\WINDOWS\system32\aspimgr.exe
aspimgr - Deleted
Restoring Windows Registry Values Restoring Windows Default Hosts File Restoring Missing Security Center Service Restoring Missing SharedAccess Service
Rebooting...
Normal Mode: Checking Files:
Trojan Files Found:
C:\-11260~1 - Deleted C:\Program Files\poolsv\YazzleBundle-1549.exe - Deleted C:\Documents and Settings\Andrew Taylor\Start Menu\Programs\Startup\TA_Start.lnk - Deleted C:\Documents and Settings\Andrew Taylor\Application Data\Install.dat - Deleted C:\Documents and Settings\Andrew Taylor\Application Data\.rdr.ini - Deleted C:\DOCUME~1\ANDREW~1\LOCALS~1\Temp\abc123.pid - Deleted C:\WINDOWS\s32.txt - Deleted C:\WINDOWS\svhost.exe - Deleted C:\WINDOWS\system32\ldinfo.ldr - Deleted C:\WINDOWS\system32\n.ini - Deleted C:\WINDOWS\tcb.pmw - Deleted C:\WINDOWS\Temp\removalfile.bat - Deleted C:\WINDOWS\ws386.ini - Deleted C:\WINDOWS\system32\drivers\runtime2.sys - Deleted
Folder C:\Documents and Settings\Andrew Taylor\Application Data\WinTouch - Removed Folder C:\Documents and Settings\All Users\Documents\Settings - Removed Folder C:\Program Files\poolsv - Removed Folder C:\Program Files\WinPop - Removed Folder C:\Temp\brr - Removed Folder C:\Temp\fse - Removed Folder C:\WINDOWS\system32\b02FdUe - Removed Folder C:\WINDOWS\system32\b06FdUe - Removed Folder C:\WINDOWS\system32\f06WtR - Removed
Removing Temp Files...
ADS Check:
C:\WINDOWS No streams found.
C:\WINDOWS\system32 No streams found.
C:\WINDOWS\system32\svchost.exe No streams found. C:\WINDOWS\system32\ntoskrnl.exe No streams found.
Final Check:
catchme 0.3.1262.1 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-11-15 09:43:56 Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
scanning hidden files ...
C:\Documents and Settings\Andrew Taylor\Cookies\andrew_taylor@sillaptak[1].txt 267 bytes
scan completed successfully hidden processes: 0 hidden services: 0 hidden files: 1
Remaining Services: ------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
Remaining Files: ---------------
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes:
Wed 1 Sep 2004 54,384 A..H. --- "C:\Program Files\America Online 9.0\aolphx.exe" Wed 1 Sep 2004 156,784 A..H. --- "C:\Program Files\America Online 9.0\aoltray.exe" Wed 1 Sep 2004 31,344 A..H. --- "C:\Program Files\America Online 9.0\RBM.exe" Tue 14 Aug 2007 230,400 ..SHR --- "C:\Program Files\s?stem32\??ool32.exe" Sun 28 Oct 2007 411,511 ..SH. --- "C:\WINDOWS\system32\cdeeg.bak1" Sun 7 Oct 2007 1,492,120 ..SH. --- "C:\WINDOWS\system32\cfhkj.bak1" Fri 9 Nov 2007 454,430 ..SH. --- "C:\WINDOWS\system32\dfhkj.bak1" Tue 4 Apr 2006 340,264 A.SH. --- "C:\WINDOWS\system32\fhkmp.bak1" Thu 6 Apr 2006 492,259 A.SH. --- "C:\WINDOWS\system32\fhkmp.bak2" Wed 3 Oct 2007 1,576,417 ..SH. --- "C:\WINDOWS\system32\gjjlm.tmp" Fri 5 Oct 2007 1,477,538 ..SH. --- "C:\WINDOWS\system32\gjjlm.bak1" Thu 4 Oct 2007 1,483,107 ..SH. --- "C:\WINDOWS\system32\gjjlm.bak2" Sun 11 Nov 2007 452,322 ..SH. --- "C:\WINDOWS\system32\kjkkj.bak1" Fri 14 Sep 2007 8,373 ..SH. --- "C:\WINDOWS\system32\kjllm.bak1" Wed 10 Oct 2007 679,105 ..SH. --- "C:\WINDOWS\system32\mlnmp.bak1" Sat 27 Oct 2007 412,411 ..SH. --- "C:\WINDOWS\system32\oqstv.bak1" Thu 15 Nov 2007 447,510 ..SH. --- "C:\WINDOWS\system32\pstwa.bak1" Tue 6 Sep 2005 182,172 A.SH. --- "C:\WINDOWS\system32\rttss.bak1" Mon 5 Sep 2005 179,540 A.SH. --- "C:\WINDOWS\system32\rttss.bak2" Wed 7 Nov 2007 429,181 ..SH. --- "C:\WINDOWS\system32\sttss.bak1" Wed 14 Nov 2007 452,293 ..SH. --- "C:\WINDOWS\system32\stvwa.bak1" Thu 25 Oct 2007 420,016 ..SH. --- "C:\WINDOWS\system32\wybeg.bak1" Thu 1 Nov 2007 419,348 ..SH. --- "C:\WINDOWS\system32\xybeg.bak1" Mon 15 Oct 2007 627,919 ..SH. --- "C:\WINDOWS\system32\ybeeg.bak1" Wed 29 Jun 2005 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak" Thu 1 Sep 2005 24,064 ...H. --- "C:\Documents and Settings\Andrew Taylor\My Documents\~WRL0001.tmp" Wed 26 Sep 2007 33,280 ...H. --- "C:\Documents and Settings\Andrew Taylor\My Documents\~WRL0002.tmp" Sun 15 Jul 2007 28,672 ...H. --- "C:\Documents and Settings\Andrew Taylor\My Documents\~WRL0005.tmp" Tue 9 Oct 2007 33,280 ...H. --- "C:\Documents and Settings\Andrew Taylor\My Documents\~WRL0006.tmp" Sun 11 Sep 2005 25,088 ...H. --- "C:\Documents and Settings\Andrew Taylor\My Documents\~WRL0021.tmp" Sun 11 Sep 2005 28,160 ...H. --- "C:\Documents and Settings\Andrew Taylor\My Documents\~WRL0056.tmp" Sun 11 Sep 2005 28,672 ...H. --- "C:\Documents and Settings\Andrew Taylor\My Documents\~WRL0305.tmp" Tue 9 Oct 2007 87,040 ...H. --- "C:\Documents and Settings\Andrew Taylor\My Documents\~WRL0480.tmp" Sun 11 Sep 2005 26,112 ...H. --- "C:\Documents and Settings\Andrew Taylor\My Documents\~WRL0485.tmp" Tue 3 Apr 2007 58,368 ...H. --- "C:\Documents and Settings\Andrew Taylor\My Documents\~WRL0564.tmp" Mon 8 Oct 2007 87,040 ...H. --- "C:\Documents and Settings\Andrew Taylor\My Documents\~WRL0585.tmp" Sun 11 Sep 2005 28,160 ...H. --- "C:\Documents and Settings\Andrew Taylor\My Documents\~WRL0958.tmp" Sun 11 Sep 2005 27,136 ...H. --- "C:\Documents and Settings\Andrew Taylor\My Documents\~WRL1307.tmp" Sat 14 Jan 2006 32,256 ...H. --- "C:\Documents and Settings\Andrew Taylor\My Documents\~WRL1315.tmp" Sun 11 Sep 2005 26,624 ...H. --- "C:\Documents and Settings\Andrew Taylor\My Documents\~WRL1522.tmp" Mon 12 Nov 2007 3,929,600 ...H. --- "C:\Documents and Settings\Andrew Taylor\My Documents\~WRL1567.tmp" Sun 15 Jul 2007 28,672 ...H. --- "C:\Documents and Settings\Andrew Taylor\My Documents\~WRL1695.tmp" Mon 23 Jan 2006 34,304 ...H. --- "C:\Documents and Settings\Andrew Taylor\My Documents\~WRL1845.tmp" Tue 3 Apr 2007 58,368 ...H. --- "C:\Documents and Settings\Andrew Taylor\My Documents\~WRL2062.tmp" Sun 11 Sep 2005 27,648 ...H. --- "C:\Documents and Settings\Andrew Taylor\My Documents\~WRL2183.tmp" Wed 26 Sep 2007 32,768 ...H. --- "C:\Documents and Settings\Andrew Taylor\My Documents\~WRL2350.tmp" Sun 11 Sep 2005 29,696 ...H. --- "C:\Documents and Settings\Andrew Taylor\My Documents\~WRL2356.tmp" Tue 9 Oct 2007 87,040 ...H. --- "C:\Documents and Settings\Andrew Taylor\My Documents\~WRL2498.tmp" Sun 15 Jul 2007 28,672 ...H. --- "C:\Documents and Settings\Andrew Taylor\My Documents\~WRL3085.tmp" Sun 15 Jul 2007 28,672 ...H. --- "C:\Documents and Settings\Andrew Taylor\My Documents\~WRL3149.tmp" Tue 9 Oct 2007 33,280 ...H. --- "C:\Documents and Settings\Andrew Taylor\My Documents\~WRL3532.tmp" Sun 11 Sep 2005 27,648 ...H. --- "C:\Documents and Settings\Andrew Taylor\My Documents\~WRL3729.tmp" Sun 11 Sep 2005 25,600 ...H. --- "C:\Documents and Settings\Andrew Taylor\My Documents\~WRL3977.tmp" Sun 11 Sep 2005 24,064 ...H. --- "C:\Documents and Settings\Andrew Taylor\My Documents\~WRL4094.tmp" Sat 18 Aug 2007 145,920 ..SHR --- "C:\Program Files\BillP Studios\WinPatrol\Setup.exe" Fri 28 Sep 2007 407 A..H. --- "C:\Program Files\InterActual\InterActual Player\iti1E0.tmp" Tue 14 Aug 2007 230,400 ..SHR --- "C:\WINDOWS\system32\F?nts\d?dplay.exe" Wed 4 Jul 2007 840 A..H. --- "C:\Program Files\Common Files\AOL\IPHSend\IPH.BAK" Wed 11 Apr 2007 8 A..H. --- "C:\Documents and Settings\Andrew Taylor\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u1\lock.tmp" Wed 11 Apr 2007 8 A..H. --- "C:\Documents and Settings\Andrew Taylor\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u2\lock.tmp" Wed 11 Apr 2007 8 A..H. --- "C:\Documents and Settings\Andrew Taylor\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u3\lock.tmp" Wed 11 Apr 2007 8 A..H. --- "C:\Documents and Settings\Andrew Taylor\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u4\lock.tmp"
Finished!
|