Sdfix:
[b]SDFix: Version 1.240 /b
Run by Marie-Christine on 04/06/2009 at 17:41
Microsoft Windows XP [version 5.1.2600]
Running From: C:\Documents and Settings\Marie-Christine\Bureau\SDFix
[b]Checking Services /b:
Restoring Default Security Values
Restoring Default Hosts File
Rebooting
[b]Checking Files /b:
Trojan Files Found:
C:\WINDOWS\SYSTEM32\SSMS.EXE - Deleted
C:\WINDOWS\system32\.exe - Deleted
C:\WINDOWS\system32\explorer.exe - Deleted
C:\WINDOWS\system32\firewall.exe - Deleted
C:\WINDOWS\system32\i - Deleted
C:\WINDOWS\system32\Isass.exe - Deleted
C:\WINDOWS\system32\logon.exe - Deleted
C:\WINDOWS\system32\ssms.exe - Deleted
Removing Temp Files
[b]ADS Check /b:
[b]Final Check /b:
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-04 17:46:40
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
[b]Remaining Services /b:
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\WINDOWS\\System32\\cbntzwoz.exe"="C:\\WINDOWS\\System32\\cbntzwoz.exe:*:Enabled:Ultimate Tool"
"C:\\WINDOWS\\System32\\gvcelny.exe"="C:\\WINDOWS\\System32\\gvcelny.exe:*:Enabled:Ultimate Tool"
"C:\\WINDOWS\\System32\\ykejf.exe"="C:\\WINDOWS\\System32\\ykejf.exe:*:Enabled:Ultimate Tool"
"\\??\\C:\\WINDOWS\\system32\\winlogon.exe"="\\??\\C:\\WINDOWS\\system32\\winlogon.exe:*:enabled:@shell32.dll,-1"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\CCleaner\\uninst.exe"="C:\\Program Files\\CCleaner\\uninst.exe:*:Enabled:Uninstall CCleaner"
"C:\\Program Files\\TeamViewer\\Version4\\TeamViewer.exe"="C:\\Program Files\\TeamViewer\\Version4\\TeamViewer.exe:*:Enabled:TeamViewer 4"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[b]Remaining Files /b:
File Backups: - C:\DOCUME~1\MARIE-~1\Bureau\SDFix\backups\backups.zip
[b]Files with Hidden Attributes /b:
Wed 3 Jun 2009 1,069,056 A..H. --- "C:\WINDOWS\system32\fxabmaa.exe"
Mon 1 Jun 2009 592,896 A..H. --- "C:\WINDOWS\system32\nsbek.exe"
Wed 3 Jun 2009 1,069,056 A..H. --- "C:\WINDOWS\system32\ojtgzdnl.exe"
Fri 2 Jun 2006 2,302,800 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\63fc91dd374f6ee602349c6eb961d9e6\BIT3F.tmp"
Thu 4 Jun 2009 45,408,615 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\8a2a5ecd72c62a4fe04757ab8c19e933\download\BIT18.tmp"
[b]Finished!/b