SDFix: Version 1.164 Run by Administrator on ne 30. 03. 2008 at 21:01
Microsoft Windows XP [Verzia 5.1.2600]
Running From: C:\SDFix
Checking Services :
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Restoring Default IE HomePage
Rebooting
Checking Files :
Trojan Files Found:
C:\WINDOWS\system32\kdhcr.exe - Deleted
C:\Program Files\NetProject\ot.ico - Deleted
C:\Program Files\NetProject\sbmdl.dll - Deleted
C:\Program Files\NetProject\sbmntr.exe - Deleted
C:\Program Files\NetProject\sbsm.exe - Deleted
C:\Program Files\NetProject\sbun.exe - Deleted
C:\Program Files\NetProject\scit.exe - Deleted
C:\Program Files\NetProject\scm.exe - Deleted
C:\Program Files\NetProject\scu.exe - Deleted
C:\Program Files\NetProject\ts.ico - Deleted
C:\Program Files\NetProject\wamdl.dll - Deleted
C:\Program Files\NetProject\waun.exe - Deleted
Folder C:\Program Files\NetProject - Removed
Removing Temp Files
ADS Check :
Final Check :
catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-03-30 21:09:22
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
IPC error: 2 Systém nemôže nájsť zadaný súbor.
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:2df9c43f
"s2"=dword:110480d0
"h0"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:eb,30,c0,f2,a5,86,0f,f2,44,7e,d8,97,a8,69,5e,8d,c2,2c,49,61,ea,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:eb,30,c0,f2,a5,86,0f,f2,44,7e,d8,97,a8,69,5e,8d,c2,2c,49,61,ea,..
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E9F81423-211E-46B6-9AE0-38568BC5CF6F}]
"DisplayName"="Alcohol 120%"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\Component Categories\{00021494-0000-0000-C000-000000000046}\Remedy Entertainment\Enum]
"Implementing"=hex:1c,00,00,00,01,00,00,00,d7,07,0b,00,01,00,1a,00,0b,00,1b,00,15,..
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\\Programi\\programi\\FlashGet\\flashget.exe"="D:\\Programi\\programi\\FlashGet\\flashget.exe:*:Enabled:FlashGet"
"C:\\Program Files\\BearShare Applications\\BearShare\\BearShare.exe"="C:\\Program Files\\BearShare Applications\\BearShare\\BearShare.exe:*:Enabled:BearShare"
"D:\\Programi\\Komunikaźn‚ programi\\ICQLite 2\\ICQLite.exe"="D:\\Programi\\Komunikaźn‚ programi\\ICQLite 2\\ICQLite.exe:*:Enabled:ICQ 5.1"
"D:\\Programi\\programi\\Hamachi\\hamachi.exe"="D:\\Programi\\programi\\Hamachi\\hamachi.exe:*:Enabled:Hamachi"
"D:\\Programi\\programi\\Internet Download Manager\\IDMan.exe"="D:\\Programi\\programi\\Internet Download Manager\\IDMan.exe:*:Enabled:Internet Download Manager"
"D:\\Programi\\Komunikaźn‚ programi\\New Folder\\Opera.exe"="D:\\Programi\\Komunikaźn‚ programi\\New Folder\\Opera.exe:*:Enabled:Opera"
"C:\\Program Files\\Outlook Express\\msimn.exe"="C:\\Program Files\\Outlook Express\\msimn.exe:*:Enabled:Outlook Express"
"D:\\Programi\\programi\\zIRC\\zirc.exe"="D:\\Programi\\programi\\zIRC\\zirc.exe:*:Enabled:zIRC"
"C:\\Program Files\\Siber Systems\\AI RoboForm\\robotaskbaricon.exe"="C:\\Program Files\\Siber Systems\\AI RoboForm\\robotaskbaricon.exe:*:Enabled:Ikona na liçte Łloh"
"D:\\Programi\\Programy\\BitComet\\BitComet.exe"="D:\\Programi\\Programy\\BitComet\\BitComet.exe:*:Enabled:BitComet - a BitTorrent Client"
"D:\\Programi\\Komunikaźn‚ programi\\ICQ\\ICQ.exe"="D:\\Programi\\Komunikaźn‚ programi\\ICQ\\ICQ.exe:*:Enabled:ICQ Library"
"D:\\Hry\\3D Live Pool\\3D Live Pool.exe"="D:\\Hry\\3D Live Pool\\3D Live Pool.exe:*:Enabled:3D Live Pool"
"D:\\Programi\\Komunikaźn‚ programi\\ICQ6\\ICQ.exe"="D:\\Programi\\Komunikaźn‚ programi\\ICQ6\\ICQ.exe:*:Enabled:ICQ6"
"C:\\Documents and Settings\\Administrator\\Desktop\\Skype.exe"="C:\\Documents and Settings\\Administrator\\Desktop\\Skype.exe:*:Enabled:Skype. Take a deep breath "
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
Remaining Files :
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes :
Mon 28 Jan 2008 1,404,240 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe"
Mon 28 Jan 2008 5,146,448 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
Mon 28 Jan 2008 2,097,488 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
Wed 15 Aug 2007 56 ..SHR --- "C:\WINDOWS\system32\3F1EAF00CB.sys"
Wed 16 Jan 2008 11,690 A.SH. --- "C:\WINDOWS\system32\KGyGaAvL.sys"
Sat 4 Aug 2007 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Wed 14 Sep 2005 4,348 A.SH. --- "C:\zal cecko\Documents and Settings\All Users\DRM\DRMv1.bak"
Thu 23 Jan 2003 65,952 A.SHR --- "C:\zal cecko\Program Files\Autodesk\Autodesk Express Viewer\Setup.exe"
Wed 14 Sep 2005 4,348 A..H. --- "C:\Documents and Settings\Administrator\My Documents\My Music\License Backup\drmv1key.bak"
Fri 8 Jun 2007 20 A..H. --- "C:\Documents and Settings\Administrator\My Documents\My Music\License Backup\drmv1lic.bak"
Wed 14 Sep 2005 312 A..H. --- "C:\Documents and Settings\Administrator\My Documents\My Music\License Backup\drmv2key.bak"
Fri 8 Jun 2007 1,536 A..H. --- "C:\Documents and Settings\Administrator\My Documents\My Music\License Backup\drmv2lic.bak"
Sat 4 Aug 2007 4,348 ...H. --- "C:\Documents and Settings\Administrator\My Documents\My Music\Z loha licencie\drmv1key.bak"
Sun 5 Aug 2007 20 A..H. --- "C:\Documents and Settings\Administrator\My Documents\My Music\Z loha licencie\drmv1lic.bak"
Sat 4 Aug 2007 312 ...H. --- "C:\Documents and Settings\Administrator\My Documents\My Music\Z loha licencie\drmv2key.bak"
Sun 5 Aug 2007 1,536 A..H. --- "C:\Documents and Settings\Administrator\My Documents\My Music\Z loha licencie\drmv2lic.bak"
Mon 27 Nov 2006 20,752 A..H. --- "C:\zal cecko\Documents and Settings\Administrator\Local Settings\Temp\1000000500029ca890022\regsvr32.exe"
Mon 27 Nov 2006 20,752 A..H. --- "C:\zal cecko\Documents and Settings\Administrator\Local Settings\Temp\400000d700029ca890022\Autorun.exe"
Wed 14 Sep 2005 4,348 A..H. --- "C:\zal cecko\Documents and Settings\Administrator\My Documents\My Music\License Backup\drmv1key.bak"
Fri 8 Jun 2007 20 A..H. --- "C:\zal cecko\Documents and Settings\Administrator\My Documents\My Music\License Backup\drmv1lic.bak"
Wed 14 Sep 2005 312 A..H. --- "C:\zal cecko\Documents and Settings\Administrator\My Documents\My Music\License Backup\drmv2key.bak"
Fri 8 Jun 2007 1,536 A..H. --- "C:\zal cecko\Documents and Settings\Administrator\My Documents\My Music\License Backup\drmv2lic.bak"
Finished!