Rapport sdfix:
SDFix: Version 1.120
Run by Gr‚gory Even on 30/12/2007 at 15:19
Microsoft Windows XP [version 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Name:
smtpdrv
Path:
System32\DRIVERS\smtpdrv.sys
smtpdrv - Deleted
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting...
Normal Mode:
Checking Files:
Trojan Files Found:
C:\ADBERD~1.EXE - Deleted
C:\PSA30S~1.EXE - Deleted
C:\Documents and Settings\Gr‚gory Even\Favoris\Online Security Guide.lnk - Deleted
C:\DOCUME~1\GRGORY~1\LOCALS~1\Temp\image015.zip - Deleted
C:\DOCUME~1\GRGORY~1\LOCALS~1\Temp\image019.zip - Deleted
C:\DOCUME~1\GRGORY~1\LOCALS~1\Temp\image023.zip - Deleted
C:\DOCUME~1\GRGORY~1\LOCALS~1\Temp\image080.zip - Deleted
C:\DOCUME~1\GRGORY~1\LOCALS~1\Temp\image108.zip - Deleted
C:\DOCUME~1\GRGORY~1\LOCALS~1\Temp\image110.zip - Deleted
C:\DOCUME~1\GRGORY~1\LOCALS~1\Temp\image112.zip - Deleted
C:\DOCUME~1\GRGORY~1\LOCALS~1\Temp\image114.zip - Deleted
C:\DOCUME~1\GRGORY~1\LOCALS~1\Temp\image115.zip - Deleted
C:\DOCUME~1\GRGORY~1\LOCALS~1\Temp\image117.zip - Deleted
C:\DOCUME~1\GRGORY~1\LOCALS~1\Temp\image119.zip - Deleted
C:\DOCUME~1\GRGORY~1\LOCALS~1\Temp\image152.zip - Deleted
C:\DOCUME~1\GRGORY~1\LOCALS~1\Temp\image68.zip - Deleted
C:\DOCUME~1\GRGORY~1\LOCALS~1\Temp\image72.zip - Deleted
C:\WINDOWS\system32\3_exception.nls - Deleted
C:\WINDOWS\system32\drivers\smtpdrv.sys - Deleted
Removing Temp Files...
ADS Check:
C:\WINDOWS
No streams found.
C:\WINDOWS\system32
No streams found.
C:\WINDOWS\system32\svchost.exe
No streams found.
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.
Final Check:
catchme 0.3.1333.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-30 15:32:13
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher]
"TracesProcessed"=dword:00000117
"TracesSuccessful"=dword:00000002
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\WINDOWS\\system32\\mshta.exe"="C:\\WINDOWS\\system32\\mshta.exe:*:Disabled:Microsoft (R) HTML Application host"
"C:\\WINDOWS\\system32\\winIogon.exe"="C:\\WINDOWS\\system32\\winIogon.exe:*:Enabled:Windows Logon Application"
"C:\\WINDOWS\\system32\\rbywxj.exe"="C:\\WINDOWS\\system32\\rbywxj.exe:*:Enabled:@xpsp2res.dll,-22005"
"C:\\WINDOWS\\system32\\qjxlbt.exe"="C:\\WINDOWS\\system32\\qjxlbt.exe:*:Enabled:@xpsp2res.dll,-22005"
"C:\\WINDOWS\\system32\\oinxw.exe"="C:\\WINDOWS\\system32\\oinxw.exe:*:Enabled:@xpsp2res.dll,-22005"
"C:\\WINDOWS\\system32\\gxsrujf.exe"="C:\\WINDOWS\\system32\\gxsrujf.exe:*:Enabled:@xpsp2res.dll,-22005"
"C:\\WINDOWS\\system32\\aqvv.exe"="C:\\WINDOWS\\system32\\aqvv.exe:*:Enabled:@xpsp2res.dll,-22005"
"C:\\WINDOWS\\system32\\macygv.exe"="C:\\WINDOWS\\system32\\macygv.exe:*:Enabled:@xpsp2res.dll,-22005"
"C:\\WINDOWS\\system32\\ljclnp.exe"="C:\\WINDOWS\\system32\\ljclnp.exe:*:Enabled:@xpsp2res.dll,-22005"
"C:\\WINDOWS\\system32\\pnlm.exe"="C:\\WINDOWS\\system32\\pnlm.exe:*:Enabled:@xpsp2res.dll,-22005"
"C:\\WINDOWS\\system32\\wnjnox.exe"="C:\\WINDOWS\\system32\\wnjnox.exe:*:Enabled:@xpsp2res.dll,-22005"
"C:\\WINDOWS\\system32\\hzunomp.exe"="C:\\WINDOWS\\system32\\hzunomp.exe:*:Enabled:@xpsp2res.dll,-22005"
"C:\\WINDOWS\\system32\\qfngywqy.exe"="C:\\WINDOWS\\system32\\qfngywqy.exe:*:Enabled:@xpsp2res.dll,-22005"
"C:\\WINDOWS\\system32\\cbac.exe"="C:\\WINDOWS\\system32\\cbac.exe:*:Enabled:@xpsp2res.dll,-22005"
"C:\\WINDOWS\\system32\\xburui.exe"="C:\\WINDOWS\\system32\\xburui.exe:*:Enabled:@xpsp2res.dll,-22005"
"C:\\WINDOWS\\system32\\ihmu.exe"="C:\\WINDOWS\\system32\\ihmu.exe:*:Enabled:@xpsp2res.dll,-22005"
"C:\\WINDOWS\\system32\\irrtn.exe"="C:\\WINDOWS\\system32\\irrtn.exe:*:Enabled:@xpsp2res.dll,-22005"
"C:\\WINDOWS\\system32\\qatbb.exe"="C:\\WINDOWS\\system32\\qatbb.exe:*:Enabled:@xpsp2res.dll,-22005"
"C:\\WINDOWS\\system32\\rjsx.exe"="C:\\WINDOWS\\system32\\rjsx.exe:*:Enabled:@xpsp2res.dll,-22005"
"C:\\WINDOWS\\system32\\xsvso.exe"="C:\\WINDOWS\\system32\\xsvso.exe:*:Enabled:@xpsp2res.dll,-22005"
"C:\\WINDOWS\\system32\\ufycugl.exe"="C:\\WINDOWS\\system32\\ufycugl.exe:*:Enabled:@xpsp2res.dll,-22005"
"C:\\WINDOWS\\system32\\apzpxze.exe"="C:\\WINDOWS\\system32\\apzpxze.exe:*:Enabled:@xpsp2res.dll,-22005"
"C:\\WINDOWS\\system32\\nkrao.exe"="C:\\WINDOWS\\system32\\nkrao.exe:*:Enabled:@xpsp2res.dll,-22005"
"C:\\WINDOWS\\system32\\xhgar.exe"="C:\\WINDOWS\\system32\\xhgar.exe:*:Enabled:@xpsp2res.dll,-22005"
"C:\\WINDOWS\\system32\\dakpdph.exe"="C:\\WINDOWS\\system32\\dakpdph.exe:*:Enabled:@xpsp2res.dll,-22005"
"C:\\WINDOWS\\system32\\othd.exe"="C:\\WINDOWS\\system32\\othd.exe:*:Enabled:@xpsp2res.dll,-22005"
"C:\\WINDOWS\\system32\\nfsmucx.exe"="C:\\WINDOWS\\system32\\nfsmucx.exe:*:Enabled:@xpsp2res.dll,-22005"
"C:\\WINDOWS\\system32\\dehf.exe"="C:\\WINDOWS\\system32\\dehf.exe:*:Enabled:@xpsp2res.dll,-22005"
"C:\\WINDOWS\\system32\\cisp.exe"="C:\\WINDOWS\\system32\\cisp.exe:*:Enabled:@xpsp2res.dll,-22005"
"C:\\WINDOWS\\system32\\dhjvmm.exe"="C:\\WINDOWS\\system32\\dhjvmm.exe:*:Enabled:@xpsp2res.dll,-22005"
"C:\\WINDOWS\\system32\\qpxtkyl.exe"="C:\\WINDOWS\\system32\\qpxtkyl.exe:*:Enabled:@xpsp2res.dll,-22005"
"C:\\WINDOWS\\system32\\fwbrwyj.exe"="C:\\WINDOWS\\system32\\fwbrwyj.exe:*:Enabled:@xpsp2res.dll,-22005"
"C:\\WINDOWS\\system32\\kgpc.exe"="C:\\WINDOWS\\system32\\kgpc.exe:*:Enabled:@xpsp2res.dll,-22005"
"C:\\WINDOWS\\system32\\wjjavwci.exe"="C:\\WINDOWS\\system32\\wjjavwci.exe:*:Enabled:@xpsp2res.dll,-22005"
"C:\\WINDOWS\\system32\\orzj.exe"="C:\\WINDOWS\\system32\\orzj.exe:*:Enabled:@xpsp2res.dll,-22005"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
Remaining Files:
---------------
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes:
Mon 19 Feb 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Wed 24 Oct 2007 57,344 ...H. --- "C:\Documents and Settings\Gr‚gory Even\Mes documents\Ecoute Clients\~WRL2717.tmp"
Thu 13 Sep 2007 433,664 ...H. --- "C:\Documents and Settings\Gr‚gory Even\Mes documents\SCAPNOR LECLERC\~WRL0001.tmp"
Fri 29 Jun 2007 19,968 ...H. --- "C:\Documents and Settings\Gr‚gory Even\Application Data\Microsoft\Word\~WRL0003.tmp"
Fri 29 Jun 2007 23,552 ...H. --- "C:\Documents and Settings\Gr‚gory Even\Application Data\Microsoft\Word\~WRL2063.tmp"
Fri 29 Jun 2007 23,040 ...H. --- "C:\Documents and Settings\Gr‚gory Even\Application Data\Microsoft\Word\~WRL3037.tmp"
Mon 24 Sep 2007 51,200 ...H. --- "C:\Documents and Settings\Gr‚gory Even\Mes documents\Animations\animation 2007\~WRL0001.tmp"
Fri 2 Feb 2007 50,176 ...H. --- "C:\Documents and Settings\Gr‚gory Even\Mes documents\SCAPNOR LECLERC\SCAPNOR\PROMO 2007\~WRL2170.tmp"
Tue 23 Jan 2007 8 A..H. --- "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch1\lock.tmp"
Tue 23 Jan 2007 8 A..H. --- "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch2\lock.tmp"
Tue 23 Jan 2007 8 A..H. --- "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch3\lock.tmp"
Tue 23 Jan 2007 8 A..H. --- "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch4\lock.tmp"
Tue 23 Jan 2007 8 A..H. --- "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch5\lock.tmp"
Tue 23 Jan 2007 8 A..H. --- "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch6\lock.tmp"
Finished!