Report.txt contents
SDFix: Version 1.240
Run by Arwine Zapanta on Sun 11/30/2008 at 09:46 PM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Checking Services :
Restoring Default Security Values
Restoring Default Hosts File
Rebooting
Checking Files :
Trojan Files Found:
C:\WINDOWS\system32\i - Deleted
Removing Temp Files
ADS Check :
[b]Final Check [/b]:
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-30 22:06:19
Windows 5.1.2600 Service Pack 3 NTFS
detected NTDLL code modification:
ZwClose
scanning hidden processes …
scanning hidden services & system hive …
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
“s1”=dword:2df9c43f
“s2”=dword:110480d0
“h0”=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
“p0”="C:\Program Files\Alcohol Soft\Alcohol 120"
“h0”=dword:00000000
“ujdew”=hex:a5,e1,ea,b6,a6,1f,b0,80,45,12,30,86,f0,4c,22,6d,4b,54,16,17,a2,…
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
“p0”="C:\Program Files\Alcohol Soft\Alcohol 120"
“h0”=dword:00000000
“ujdew”=hex:a5,e1,ea,b6,a6,1f,b0,80,45,12,30,86,f0,4c,22,6d,4b,54,16,17,a2,…
scanning hidden registry entries …
source file error: C:\Documents and Settings\Rowin Zapanta\ntuser.dat
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
“%windir%\Network Diagnostic\xpnetdiag.exe”=“%windir%\Network Diagnostic\xpnetdiag.exe::Enabled:@xpsp3res.dll,-20000"
“%windir%\system32\sessmgr.exe”="%windir%\system32\sessmgr.exe::enabled:@xpsp2res.dll,-22019”
“C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE”=“C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE::Enabled:Microsoft Office Outlook"
“C:\Program Files\Microsoft Office\Office12\GROOVE.EXE”="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE::Enabled:Microsoft Office Groove”
“C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE”=“C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE::Enabled:Microsoft Office OneNote"
“C:\Program Files\IEPro\MiniDM.exe”="C:\Program Files\IEPro\MiniDM.exe::Enabled:MiniDM”
“C:\Program Files\uTorrent\uTorrent.exe”=“C:\Program Files\uTorrent\uTorrent.exe::Enabled:æTorrent"
“C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe”="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe::Enabled:Yahoo! Messenger”
“C:\Program Files\Windows Live\Messenger\msnmsgr.exe”=“C:\Program Files\Windows Live\Messenger\msnmsgr.exe::Enabled:Windows Live Messenger"
“C:\Program Files\Windows Live\Messenger\livecall.exe”="C:\Program Files\Windows Live\Messenger\livecall.exe::Enabled:Windows Live Messenger (Phone)”
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
“%windir%\Network Diagnostic\xpnetdiag.exe”=“%windir%\Network Diagnostic\xpnetdiag.exe::Enabled:@xpsp3res.dll,-20000"
“%windir%\system32\sessmgr.exe”="%windir%\system32\sessmgr.exe::enabled:@xpsp2res.dll,-22019”
“C:\Program Files\Windows Live\Messenger\msnmsgr.exe”=“C:\Program Files\Windows Live\Messenger\msnmsgr.exe::Enabled:Windows Live Messenger"
“C:\Program Files\Windows Live\Messenger\livecall.exe”="C:\Program Files\Windows Live\Messenger\livecall.exe::Enabled:Windows Live Messenger (Phone)”
Remaining Files :
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes :
Wed 22 Oct 2008 949,072 A.SHR — “C:\Program Files\Spybot - Search & Destroy\advcheck.dll”
Mon 15 Sep 2008 1,562,960 A.SHR — “C:\Program Files\Spybot - Search & Destroy\SDHelper.dll”
Mon 7 Jul 2008 1,429,840 A.SHR — “C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe”
Mon 7 Jul 2008 4,891,472 A.SHR — “C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe”
Tue 16 Sep 2008 1,833,296 A.SHR — “C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe”
Wed 22 Oct 2008 962,896 A.SHR — “C:\Program Files\Spybot - Search & Destroy\Tools.dll”
Wed 3 May 2006 163,328 …SHR — “C:\WINDOWS\system32\flvDX.dll”
Wed 21 Feb 2007 31,232 …SHR — “C:\WINDOWS\system32\msfDX.dll”
Mon 17 Dec 2007 27,648 …SH. — “C:\WINDOWS\system32\Smab0.dll”
Sun 26 Jun 2005 616,448 …SHR — “C:\Program Files\eRightSoft\SUPER\cygwin1.dll”
Wed 22 Jun 2005 45,568 …SHR — “C:\Program Files\eRightSoft\SUPER\cygz.dll”
Thu 29 May 2008 72,704 …SHR — “C:\Program Files\eRightSoft\SUPER\Setup.exe”
Tue 4 Jun 2002 84,992 …HR — “C:\Program Files\eRightSoft\SUPER\mencoder\14_43260.dll”
Tue 4 Jun 2002 44,032 …HR — “C:\Program Files\eRightSoft\SUPER\mencoder\28_83260.dll”
Tue 10 Dec 2002 73,766 …HR — “C:\Program Files\eRightSoft\SUPER\mencoder\atrc3260.dll”
Tue 10 Dec 2002 65,575 …HR — “C:\Program Files\eRightSoft\SUPER\mencoder\cook3260.dll”
Mon 10 Jun 2002 36,864 …HR — “C:\Program Files\eRightSoft\SUPER\mencoder\ddnt3260.dll”
Tue 4 Jun 2002 20,480 …HR — “C:\Program Files\eRightSoft\SUPER\mencoder\dnet3260.dll”
Tue 10 Dec 2002 102,437 …HR — “C:\Program Files\eRightSoft\SUPER\mencoder\drv13260.dll”
Tue 10 Dec 2002 176,165 …HR — “C:\Program Files\eRightSoft\SUPER\mencoder\drv23260.dll”
Tue 10 Dec 2002 208,935 …HR — “C:\Program Files\eRightSoft\SUPER\mencoder\drv33260.dll”
Tue 10 Dec 2002 217,127 …HR — “C:\Program Files\eRightSoft\SUPER\mencoder\drv43260.dll”
Mon 10 Jun 2002 40,448 …HR — “C:\Program Files\eRightSoft\SUPER\mencoder\dspr3260.dll”
Sun 4 Nov 2001 225,280 …HR — “C:\Program Files\eRightSoft\SUPER\mencoder\ivvideo.dll”
Tue 10 Apr 2001 225,280 …HR — “C:\Program Files\eRightSoft\SUPER\mencoder\qtmlClient.dll”
Fri 20 Feb 2004 232,960 …HR — “C:\Program Files\eRightSoft\SUPER\mencoder\raac.dll”
Mon 10 Jun 2002 525,824 …HR — “C:\Program Files\eRightSoft\SUPER\mencoder\rnco3260.dll”
Tue 10 Dec 2002 245,805 …HR — “C:\Program Files\eRightSoft\SUPER\mencoder\rnlt3260.dll”
Tue 10 Dec 2002 45,093 …HR — “C:\Program Files\eRightSoft\SUPER\mencoder\rv103260.dll”
Tue 10 Dec 2002 98,341 …HR — “C:\Program Files\eRightSoft\SUPER\mencoder\rv203260.dll”
Tue 10 Dec 2002 94,247 …HR — “C:\Program Files\eRightSoft\SUPER\mencoder\rv303260.dll”
Tue 10 Dec 2002 90,151 …HR — “C:\Program Files\eRightSoft\SUPER\mencoder\rv403260.dll”
Tue 10 Dec 2002 102,439 …HR — “C:\Program Files\eRightSoft\SUPER\mencoder\sipr3260.dll”
Mon 10 Jun 2002 49,152 …HR — “C:\Program Files\eRightSoft\SUPER\mencoder\tokr3260.dll”
Thu 20 Mar 2008 5,632 …SHR — “C:\Program Files\eRightSoft\SUPER\spk\1stRun.exe”
Finished!