SDFix: Version 1.91
Run by Administratr on 2007-07-21 at 13:40
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Name:
ICF
msupdate
NtmlSvc
windev-2533-376
xpdx
ImagePath:
\??\C:\WINDOWS\system32\xpdx.sys
xpdx - Deleted
Killing PID 136 'smss.exe'
Killing PID 212 'winlogon.exe'
ndis.sys Infected!
Patched File copied to Backups Folder
Attempting to replace ndis.sys with original version...
Original ndis.sys Restored
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting...
Normal Mode:
Checking Files:
Trojan Files Found:
C:\WINDOWS\system32\windev-2533-376.sys - Deleted
C:\WINDOWS\SYSTEM32\PF5607~1.DLL - Deleted
C:\WINDOWS\SYSTEM32\PF9452~1.DLL - Deleted
C:\WINDOWS\SYSTEM32\PFB0E0~1.DLL - Deleted
C:\WINDOWS\SYSTEM32\PFCA7F~1.DLL - Deleted
C:\WINDOWS\SYSTEM32\PFXZMT~1.DLL - Deleted
C:\WINDOWS\SYSTEM32\PFXZMT~2.DLL - Deleted
C:\WINDOWS\SYSTEM32\PFXZMT~3.DLL - Deleted
C:\WINDOWS\SYSTEM32\PFXZMT~4.DLL - Deleted
C:\Documents and Settings\Evelina\Lokala instllningar\Temp\1.dllb - Deleted
C:\Documents and Settings\Evelina\Lokala instllningar\Temp\2.dllb - Deleted
C:\Documents and Settings\Evelina\Lokala instllningar\Temp\5.dllb - Deleted
C:\Documents and Settings\Evelina\Lokala instllningar\Temp\6.dllb - Deleted
C:\Documents and Settings\Evelina\Lokala instllningar\Temp\7.dllb - Deleted
C:\WINDOWS\system32\gmc.exe.exe - Deleted
C:\WINDOWS\ServicePackFiles\
www.google.com\favicon.ico - Deleted
C:\WINDOWS\ServicePackFiles\
www.google.com\index.html - Deleted
C:\WINDOWS\ServicePackFiles\
www.google.com\thank.html - Deleted
C:\WINDOWS\ServicePackFiles\
www.google.com\Google_files\hp0.gif - Deleted
C:\WINDOWS\ServicePackFiles\
www.google.com\Google_files\hp1.gif - Deleted
C:\WINDOWS\ServicePackFiles\
www.google.com\Google_files\hp2.gif - Deleted
C:\WINDOWS\ServicePackFiles\
www.google.com\Google_files\hp3.gif - Deleted
C:\Program\Delade filer\Microsoft Shared\Web Folders\ibm00001.dll - Deleted
C:\Program\Delade filer\Microsoft Shared\Web Folders\ibm00002.dll - Deleted
C:\install\credits.bat - Deleted
C:\install\ghost.exe - Deleted
C:\install\install.exe - Deleted
C:\WINDOWS\b122.exe - Deleted
C:\WINDOWS\b128.exe - Deleted
C:\WINDOWS\desktop.html - Deleted
C:\WINDOWS\myalbum2007.zip - Deleted
C:\WINDOWS\retadpu27.exe - Deleted
C:\WINDOWS\retadpu420.exe - Deleted
C:\WINDOWS\retadpu444.exe - Deleted
C:\WINDOWS\ServicePackFiles\mm7059.exe - Deleted
C:\WINDOWS\ServicePackFiles\services.exe - Deleted
C:\WINDOWS\system32\arcac.exe - Deleted
C:\WINDOWS\system32\arcac.exe.bak - Deleted
C:\WINDOWS\system32\drivers\asc3550u.sys - Deleted
C:\WINDOWS\system32\drivers\etc\hosts.tim - Deleted
C:\WINDOWS\system32\max1d1164v.exe - Deleted
C:\WINDOWS\system32\msvcrtd.exe - Deleted
C:\WINDOWS\system32\rpcc.dll - Deleted
C:\WINDOWS\system32\spoolsvv.exe - Deleted
C:\WINDOWS\system32\svcp.csv - Deleted
C:\WINDOWS\system32\syshelps.dll - Deleted
C:\WINDOWS\system32\sysprinters.dll - Deleted
C:\WINDOWS\system32\vx.tll - Deleted
C:\WINDOWS\system32\windev-peers.ini - Deleted
C:\WINDOWS\system32\winsub.xml - Deleted
C:\WINDOWS\Temp\$_2341233.TMP - Deleted
C:\WINDOWS\Temp\$_2341234.TMP - Deleted
C:\WINDOWS\Temp\$b17a2e8.tmp - Deleted
C:\WINDOWS\winvip.exe - Deleted
C:\WINDOWS\wr.txt - Deleted
C:\WINDOWS\xpupdate.exe - Deleted
C:\SDFix\backups_old1\1.dllb - Deleted
C:\SDFix\backups_old1\2.dllb - Deleted
C:\SDFix\backups_old1\5.dllb - Deleted
C:\SDFix\backups_old1\6.dllb - Deleted
C:\SDFix\backups_old1\7.dllb - Deleted
C:\WINDOWS\system32\xpdx.sys - Deleted
Folder C:\Program\InetGet2 - Removed
Folder C:\WINDOWS\ServicePackFiles\
www.google.com - Removed
Removing Temp Files...
ADS Check:
C:\WINDOWS
No streams found.
C:\WINDOWS\system32
No streams found.
C:\WINDOWS\system32\svchost.exe
No streams found.
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.
Final Check:
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\sharedaccess\parameters\firewallpolicy\standard profile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\syste m32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\sharedaccess\parameters\firewallpolicy\domainpr ofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\syste m32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
Remaining Files:
---------------
Backups Folder: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes:
C:\Documents and Settings\All Users\Dokument\Settings\bot.dll
C:\Documents and Settings\Evelina\Application Data\?asks\?hkdsk.exe
C:\Program\Common Files\T?sks\winlogon.exe
C:\Program\Common Files\T?sks\winlogon.exe~
C:\Program\Delade filer\Yazzle1122OinAdmin.exe
C:\Program\Delade filer\Yazzle1122OinUninstaller.exe
C:\System Volume Information\_restore{AB37CA35-D5E5-4C09-8173-B56A93CC4D61}\RP903\A0223860.exe
C:\System Volume Information\_restore{AB37CA35-D5E5-4C09-8173-B56A93CC4D61}\RP908\A0232170.exe
C:\System Volume Information\_restore{AB37CA35-D5E5-4C09-8173-B56A93CC4D61}\RP910\A0234370.exe
C:\Documents and Settings\Evelina\Skrivbord\Evelina\~WRL1431.tmp
C:\Documents and Settings\Evelina\Skrivbord\Evelina\~WRL3417.tmp
C:\Documents and Settings\Gabriel\Skrivbord\Arbeten\Eng\~WRL0544.tm p
C:\Documents and Settings\Gabriel\Skrivbord\Arbeten\Eng\~WRL1006.tm p
C:\Documents and Settings\Gabriel\Skrivbord\Arbeten\Eng\~WRL3414.tm p
C:\Program Files\InterActual\InterActual Player\iti2.tmp
C:\Documents and Settings\Gabriel\Lokala instllningar\Temp\Temporr katalog 1 fr 060720_Segling_Small.zip\060720_Segling_Small\Thum bs.db
Finished