le voila;
[b]SDFix: Version 1.240
/b
Run by jultonus on 06/02/2009 at 17:38
Microsoft Windows XP [version 5.1.2600]
Running From: C:\SDFix
[b]Checking Services
/b:
Restoring Default Security Values
Restoring Default Hosts File
Rebooting
[b]Checking Files
/b:
Trojan Files Found:
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP10.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP11.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP12.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP13.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP14.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP15.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP16.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP17.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP18.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP19.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP1A.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP1B.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP1C.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP1D.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP1E.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP1F.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP2.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP20.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP21.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP22.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP23.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP24.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP25.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP26.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP27.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP28.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP29.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP2A.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP2B.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP2C.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP2D.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP2E.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP2F.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP3.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP30.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP31.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP32.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP33.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP34.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP35.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP36.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP37.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP38.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP39.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP3A.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP3B.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP3C.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP3D.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP3E.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP3F.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP4.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP40.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP41.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP42.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP43.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP44.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP45.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP46.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP47.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP48.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP49.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP4A.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP4B.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP4C.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP4D.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP4E.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP4F.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP5.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP50.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP51.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP52.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP53.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP54.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP55.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP56.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP57.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP58.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP59.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP5A.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP5B.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP5C.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP5D.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP5E.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP5F.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP6.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP60.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP61.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP62.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP63.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP64.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP65.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP66.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP67.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP68.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP69.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP6A.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP6B.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP6C.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP6D.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP6E.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP6F.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP7.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP8.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMP9.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMPA.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMPB.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMPC.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMPD.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMPE.tmp - Deleted
C:\DOCUME~1\jultonus\LOCALS~1\Temp\TMPF.tmp - Deleted
Removing Temp Files
[b]ADS Check
/b:
[b]Final Check
/b:
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-02-06 17:40:29
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\ESENT]
"EventMessageFile"=str(2):"c:\windows\system32\ESENT.dll"
"CategoryMessageFile"=str(2):"c:\windows\system32\ESENT.dll"
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
[b]Remaining Services
/b:
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\\Program Files\\CyberLink\\PowerDVD8\\PowerDVD8.exe"="C:\\Program Files\\CyberLink\\PowerDVD8\\PowerDVD8.exe:*:Enabled:CyberLink PowerDVD 8.0"
"C:\\Program Files\\ma-config.com\\maconfservice.exe"="C:\\Program Files\\ma-config.com\\maconfservice.exe:LocalSubNet:Enabled:maconfservice"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\eMule\\emule.exe"="C:\\Program Files\\eMule\\emule.exe:*:Enabled:eMule"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"="C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\WINDOWS\\system32\\Isass.exe"="C:\\WINDOWS\\system32\\Isass.exe:*:Disabled:Isass"
"C:\\WINDOWS\\system32\\explorer.exe"="C:\\WINDOWS\\system32\\explorer.exe:*:Disabled:explorer"
"C:\\WINDOWS\\system32\\csrs.exe"="C:\\WINDOWS\\system32\\csrs.exe:*:Enabled:csrs"
"C:\\WINDOWS\\system32\\winamp.exe"="C:\\WINDOWS\\system32\\winamp.exe:*:Disabled:winamp"
"C:\\WINDOWS\\system32\\lssas.exe"="C:\\WINDOWS\\system32\\lssas.exe:*:Enabled:lssas"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\CyberLink\\PowerDVD8\\PowerDVD8.exe"="C:\\Program Files\\CyberLink\\PowerDVD8\\PowerDVD8.exe:*:Enabled:CyberLink PowerDVD 8.0"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"="C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
[b]Remaining Files
/b:
File Backups: - C:\SDFix\backups\backups.zip
[b]Files with Hidden Attributes
/b:
Wed 4 Feb 2009 49,202 ..SHR --- "C:\WINDOWS\wswc.exe"
Thu 5 Feb 2009 56 ..SHR --- "C:\WINDOWS\system32\B8AEFE78D0.sys"
Thu 5 Feb 2009 10,022 A.SH. --- "C:\WINDOWS\system32\KGyGaAvL.sys"
[b]Finished!
/b