Restoring Default Security Values
Restoring Default Hosts File
Rebooting
Checking Files :
Trojan Files Found:
C:\WINDOWS\system32\lm.dat - Deleted
C:\WINDOWS\system32\tb.dr - Deleted
Removing Temp Files
ADS Check :
Final Check :
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-01-21 23:32:06
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS]
"Start"=dword:00000003
scanning hidden registry entries ...
scanning hidden files ...
C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb00018.log 131072 bytes
C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb00019.log
C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb0001A.log
C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb0001B.log
C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb0001C.log
C:\WINDOWS\KB950974.log 4797 bytes
C:\WINDOWS\KB951978.log 4729 bytes
C:\WINDOWS\KB952954.log 4724 bytes
C:\WINDOWS\KB954459.log 4799 bytes
C:\WINDOWS\LastGood
C:\WINDOWS\LastGood\INF
C:\WINDOWS\LastGood\INF\oem72.inf 0 bytes
C:\WINDOWS\LastGood\INF\oem72.PNF 0 bytes
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 13
Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
Remaining Files :
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes :
Sun 13 Apr 2008 1,695,232 ..SH. --- "C:\Program Files\Messenger\msmsgs.exe"
Sun 13 Apr 2008 60,416 A.SH. --- "C:\Program Files\Outlook Express\msimn.exe"
Wed 22 Oct 2008 949,072 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\advcheck.dll"
Mon 15 Sep 2008 1,562,960 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SDHelper.dll"
Thu 14 Aug 2008 1,429,840 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe"
Wed 30 Jul 2008 4,891,984 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
Wed 22 Oct 2008 962,896 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\Tools.dll"
Tue 8 Apr 2008 88 ..SHR --- "C:\WINDOWS\system32\268D29694B.sys"
Tue 8 Apr 2008 2,516 A.SH. --- "C:\WINDOWS\system32\KGyGaAvL.sys"
Thu 16 Aug 2007 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Wed 29 Aug 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Wed 21 Jan 2009 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\158e67e5edd92c78c30c06dd18cea563\BIT11.tmp"
Wed 21 Jan 2009 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\2ad1413c5dc0d16e6d56d3e6ca94ed48\BIT9.tmp"
Wed 21 Jan 2009 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\44b76335ab66b3f67d14b905f9332d93\BIT8.tmp"
Wed 21 Jan 2009 5,687,304 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\5b2daa6ebd73054162f60f3f53f1dca9\BIT5.tmp"
Wed 21 Jan 2009 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\74031615b462b8e5d2990107f3910ffb\BITE.tmp"
Wed 21 Jan 2009 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\786d4f3a5b0751315ce27a615486aa06\BITD.tmp"
Wed 21 Jan 2009 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\85c89a67d8ff3b695dc544d738998335\BIT12.tmp"
Wed 21 Jan 2009 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\a09e4d6c8ef6df2d966f9bd348e8cd41\BITF.tmp"
Wed 21 Jan 2009 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\a37ea2d49e8a7659886ac76c226cad7d\BIT6.tmp"
Wed 21 Jan 2009 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\adb12c2fbe14079cc25ea0a86851c595\BIT7.tmp"
Wed 21 Jan 2009 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\c47336b4131812a4d1c2451b65456451\BIT10.tmp"
Wed 21 Jan 2009 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\e962c8f11a38ea73664a66d8ce03b0f5\BITA.tmp"
Finished!