SDFix: Version 1.113
Run by Praz-el on Thu 11/01/2007 at 02:16 PM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\DOCUME~1\Praz-el\Desktop\SDFix
Safe Mode:
Checking Services:
Name:
Driver
ImagePath:
\??\C:\WINDOWS\system32\frmwrk.sys
Driver - Deleted
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting...
Normal Mode:
Checking Files:
Trojan Files Found:
C:\11.TMP - Deleted
C:\12.TMP - Deleted
C:\14.TMP - Deleted
C:\16.TMP - Deleted
C:\E.TMP - Deleted
C:\F.TMP - Deleted
C:\WINDOWS\SYSTEM32\CENTER.EXE - Deleted
C:\WINDOWS\dat.txt - Deleted
C:\WINDOWS\rs.txt - Deleted
C:\WINDOWS\system32\0_exception.nls - Deleted
C:\WINDOWS\system32\alert_icon.gif - Deleted
C:\WINDOWS\system32\b.gif - Deleted
C:\WINDOWS\system32\backtomsn.gif - Deleted
C:\WINDOWS\system32\backtomsn.jpg - Deleted
C:\WINDOWS\system32\classifields.gif - Deleted
C:\WINDOWS\system32\close_icon.gif - Deleted
C:\WINDOWS\system32\cmds.txt - Deleted
C:\WINDOWS\system32\conf.dat - Deleted
C:\WINDOWS\system32\cookie1.dat - Deleted
C:\WINDOWS\system32\down_arrow.gif - Deleted
C:\WINDOWS\system32\frmwrk.sys - Deleted
C:\WINDOWS\system32\google.htm - Deleted
C:\WINDOWS\system32\header_bg.gif - Deleted
C:\WINDOWS\system32\hf_en-US.js - Deleted
C:\WINDOWS\system32\home.htm - Deleted
C:\WINDOWS\system32\icon_warning.gif - Deleted
C:\WINDOWS\system32\images.gif - Deleted
C:\WINDOWS\system32\info.txt - Deleted
C:\WINDOWS\system32\jewel.png - Deleted
C:\WINDOWS\system32\l_sb.css - Deleted
C:\WINDOWS\system32\l_sb_c.js - Deleted
C:\WINDOWS\system32\ma_search_1.gif - Deleted
C:\WINDOWS\system32\maps.gif - Deleted
C:\WINDOWS\system32\more.gif - Deleted
C:\WINDOWS\system32\msn.htm - Deleted
C:\WINDOWS\system32\news.gif - Deleted
C:\WINDOWS\system32\passport.gif - Deleted
C:\WINDOWS\system32\ps1.dat - Deleted
C:\WINDOWS\system32\rc.dat - Deleted
C:\WINDOWS\system32\remove_spyware_button.gif - Deleted
C:\WINDOWS\system32\search.css - Deleted
C:\WINDOWS\system32\sec.htm - Deleted
C:\WINDOWS\system32\secuity_center_logo.gif - Deleted
C:\WINDOWS\system32\simcard1.dll - Deleted
C:\WINDOWS\system32\SrchBtn.gif - Deleted
C:\WINDOWS\system32\toolbar_bg.gif - Deleted
C:\WINDOWS\system32\toolbar_corner_left.gif - Deleted
C:\WINDOWS\system32\toolbar_corner_right.gif - Deleted
C:\WINDOWS\system32\warn.htm - Deleted
C:\WINDOWS\system32\web.gif - Deleted
C:\WINDOWS\system32\yahoo.htm - Deleted
C:\WINDOWS\system32\ysch_srp_gsp2_20070621.js - Deleted
C:\WINDOWS\system32\yschx_20070405.css - Deleted
Removing Temp Files...
ADS Check:
C:\WINDOWS
No streams found.
C:\WINDOWS\system32
No streams found.
C:\WINDOWS\system32\svchost.exe
No streams found.
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.
Final Check:
catchme 0.3.1253 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-11-01 14:23:05
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\Program Files\\CAPCOM\\LOST_PLANET_TRIAL_DX9\\LostPlanetDX9.exe"="C:\\Program Files\\CAPCOM\\LOST_PLANET_TRIAL_DX9\\LostPlanetDX9.exe


isabled:LostPlanetDX9"
"C:\\Program Files\\Codemasters\\Overlord\\Overlord.exe"="C:\\Program Files\\Codemasters\\Overlord\\Overlord.exe

:Enabled:Overlord"
"C:\\Documents and Settings\\Praz-el\\Desktop\\utorrent.exe"="C:\\Documents and Settings\\Praz-el\\Desktop\\utorrent.exe

:Enabled:æTorrent"
"C:\\Program Files\\Steam\\Steam.exe"="C:\\Program Files\\Steam\\Steam.exe

:Enabled

team Client"
"C:\\Program Files\\Steam\\Steamapps\\tecknomasta2004@yahoo.com\\source sdk base\\hl2.exe"="C:\\Program Files\\Steam\\Steamapps\\tecknomasta2004@yahoo.com\\source sdk base\\hl2.exe

:Enabled:hl2"
"C:\\Program Files\\Steam\\Steamapps\\tecknomasta2004@yahoo.com\\half-life 2 deathmatch\\hl2.exe"="C:\\Program Files\\Steam\\Steamapps\\tecknomasta2004@yahoo.com\\half-life 2 deathmatch\\hl2.exe

:Enabled:hl2"
"C:\\Program Files\\Steam\\Steamapps\\tecknomasta2004@yahoo.com\\half-life 2\\hl2.exe"="C:\\Program Files\\Steam\\Steamapps\\tecknomasta2004@yahoo.com\\half-life 2\\hl2.exe

:Enabled:hl2"
"C:\\Program Files\\Fury\\Binaries\\DiamondWare\\dwTVC.exe"="C:\\Program Files\\Fury\\Binaries\\DiamondWare\\dwTVC.exe

:Enabled:dwTVC"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe

:Enabled:LimeWire"
"D:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"="D:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe

:Enabled:Blizzard Downloader"
"C:\\Program Files\\Sierra Entertainment\\World in Conflict\\wic.exe"="C:\\Program Files\\Sierra Entertainment\\World in Conflict\\wic.exe

:Enabled:World in Conflict"
"C:\\Program Files\\Sierra Entertainment\\World in Conflict\\wic_online.exe"="C:\\Program Files\\Sierra Entertainment\\World in Conflict\\wic_online.exe

:Enabled:World in Conflict - Online Only"
"C:\\Program Files\\Sierra Entertainment\\World in Conflict\\wic_ds.exe"="C:\\Program Files\\Sierra Entertainment\\World in Conflict\\wic_ds.exe

:Enabled:World in Conflict - Dedicated Server"
"C:\\Program Files\\Steam\\Steamapps\\tecknomasta2004@yahoo.com\\garrysmod\\hl2.exe"="C:\\Program Files\\Steam\\Steamapps\\tecknomasta2004@yahoo.com\\garrysmod\\hl2.exe

:Enabled:hl2"
"C:\\Program Files\\Steam\\Steamapps\\tecknomasta2004@yahoo.com\\team fortress 2\\hl2.exe"="C:\\Program Files\\Steam\\Steamapps\\tecknomasta2004@yahoo.com\\team fortress 2\\hl2.exe

:Enabled:hl2"
"%windir%\\system32\\winav.exe"="%windir%\\system32\\winav.exe

:Enabled

xpsp2res.dll,-22019"
"C:\\WINDOWS\\system32\\48393902ld.exe"="C:\\WINDOWS\\system32\\48393902ld.exe

:Enabled:Enabled"
"C:\\Program Files\\Electronic Arts\\Crytek\\Crysis SP Demo\\Bin32\\Crysis.exe"="C:\\Program Files\\Electronic Arts\\Crytek\\Crysis SP Demo\\Bin32\\Crysis.exe

:Enabled:Crysis_32_sp_demo"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe

:enabled

xpsp2res.dll,-22019"
"%windir%\\system32\\winav.exe"="%windir%\\system32\\winav.exe

:Enabled

xpsp2res.dll,-22019"
Remaining Files:
---------------
File Backups: - C:\DOCUME~1\Praz-el\Desktop\SDFix\backups\backups.zip
Files with Hidden Attributes:
Thu 25 Oct 2007 16,954 ...HR --- "C:\WINDOWS\system32\win_4s.exe"
Sun 28 Oct 2007 4,579 ...HR --- "C:\Documents and Settings\Praz-el\Application Data\SecuROM\UserData\securom_v7_01.bak"
Finished!