[b]SDFix: Version 1.207 [/b] Run by [removed] on Tue 07/22/2008 at 10:43 AM Microsoft Windows XP [Version 5.1.2600] Running From: C:\DOCUME~1\SMOHAP~1\Desktop\SDFix [b]Checking Services [/b]: Restoring Default Security Values Restoring Default Hosts File Rebooting [b]Checking Files [/b]: Trojan Files Found: C:\Documents and Settings\SMOHAPATRA1\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.redtube.com\settings.sol - Deleted C:\DOCUME~1\SMOHAP~1\LOCALS~1\Temp\TMP3A.tmp - Deleted C:\DOCUME~1\SMOHAP~1\LOCALS~1\Temp\tmp24.tmp - Deleted C:\WINNT\system32\dlh9jkdq8.exe - Deleted C:\WINNT\system32\vx.tll - Deleted Folder C:\Documents and Settings\SMOHAPATRA1\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.redtube.com - Removed Removing Temp Files [b]ADS Check [/b]: [b]Final Check [/b]: catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-07-22 10:49:41 Windows 5.1.2600 Service Pack 2 FAT NTAPI scanning hidden processes ... scanning hidden services ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden processes: 0 hidden services: 0 hidden files: 0 [b]Remaining Services [/b]: Authorized Application Key Export: [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger" "C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server" "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger" "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)" "C:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"="C:\\Program Files\\MySpace\\IM\\MySpaceIM.exe:*:Enabled:MySpaceIM" [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger" "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)" [b]Remaining Files [/b]: File Backups: - C:\DOCUME~1\SMOHAP~1\Desktop\SDFix\backups\backups.zip [b]Files with Hidden Attributes [/b]: Wed 4 Jan 2006 953 A.SH. --- "C:\WINNT\system32\mmf.sys" Sat 26 Jan 2008 48 A.SH. --- "C:\Documents and Settings\All Users\DRM\v2ks.sec.bak" Sat 26 Jan 2008 400 A.SH. --- "C:\Documents and Settings\All Users\DRM\v2ks.bla.bak" Sat 26 Jan 2008 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak" Sat 26 Jan 2008 400 A.SH. --- "C:\Documents and Settings\All Users\DRM\v3ks.bla.bak" Fri 24 Jan 2003 65,952 ..SHR --- "C:\Program Files\Autodesk\Autodesk Express Viewer\Setup.exe" Wed 7 May 2008 0 A..H. --- "C:\WINNT\SoftwareDistribution\Download\385cb67dda0ffd4dea8c0d990dc65796\BIT84.tmp" Wed 12 Dec 2007 6,934,488 A..H. --- "C:\WINNT\SoftwareDistribution\Download\b6b8211a5dc0636ae3d15bf626ce10d3\BIT34.tmp" Sat 12 Jul 2008 1,131,560 A..H. --- "C:\WINNT\SoftwareDistribution\Download\94e2de28cb8ee27606822ca199876d4a\BIT2A.tmp" Sun 20 Jul 2008 0 A..H. --- "C:\WINNT\SoftwareDistribution\Download\fd0264849c01086f3c6b505dc02dbd44\BITCF.tmp" Wed 16 Jul 2008 0 A..H. --- "C:\WINNT\SoftwareDistribution\Download\85d72ebd3332986fe72a8378dc1d1a21\BIT3.tmp" Mon 21 Jul 2008 1,131,560 A..H. --- "C:\WINNT\SoftwareDistribution\Download\d8d19e7b16e1dafba6906abfdd61b4f9\BITD8.tmp" Thu 22 Nov 2007 0 A..H. --- "C:\WINNT\SoftwareDistribution\Download\410ff09308a833491dba7686f0aee2eb\BIT12.tmp" Tue 27 Nov 2007 478,960 A..H. --- "C:\WINNT\SoftwareDistribution\Download\208c1a8c52f47d7b2df4baa21f58d3da\BIT7.tmp" Tue 15 Jul 2008 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp" Sun 27 Jan 2008 20 A..H. --- "C:\Documents and Settings\SMOHAPATRA1\My Documents\My Music\License Backup\drmv1lic.bak" Sat 26 Jan 2008 4,348 ...H. --- "C:\Documents and Settings\SMOHAPATRA1\My Documents\My Music\License Backup\drmv1key.bak" Sun 27 Jan 2008 1,536 A..H. --- "C:\Documents and Settings\SMOHAPATRA1\My Documents\My Music\License Backup\drmv2lic.bak" Sat 26 Jan 2008 488 ...H. --- "C:\Documents and Settings\SMOHAPATRA1\My Documents\My Music\License Backup\drmv2key.bak" Fri 18 Nov 2005 29,696 ...H. --- "C:\Documents and Settings\SMOHAPATRA1\Application Data\Microsoft\Templates\~WRL0004.tmp" Thu 27 Dec 2007 19,968 ...H. --- "C:\Documents and Settings\SMOHAPATRA1\Application Data\Microsoft\Word\~WRL0004.tmp" Mon 3 Mar 2008 19,456 ...H. --- "C:\Documents and Settings\SMOHAPATRA1\Application Data\Microsoft\Word\~WRL0003.tmp" Mon 3 Mar 2008 19,968 ...H. --- "C:\Documents and Settings\SMOHAPATRA1\Application Data\Microsoft\Word\~WRL0005.tmp" Sat 15 Mar 2008 30,720 ...H. --- "C:\Documents and Settings\SMOHAPATRA1\Application Data\Microsoft\Word\~WRL0006.tmp" Tue 6 May 2008 19,456 ...H. --- "C:\Documents and Settings\SMOHAPATRA1\Application Data\Microsoft\Word\~WRL0007.tmp" Wed 7 May 2008 25,088 ...H. --- "C:\Documents and Settings\SMOHAPATRA1\Application Data\Microsoft\Word\~WRL2929.tmp" Tue 20 May 2008 19,456 ...H. --- "C:\Documents and Settings\SMOHAPATRA1\Application Data\Microsoft\Word\~WRL0008.tmp" Tue 20 May 2008 19,456 ...H. --- "C:\Documents and Settings\SMOHAPATRA1\Application Data\Microsoft\Word\~WRL2967.tmp" Mon 9 Jun 2008 19,968 ...H. --- "C:\Documents and Settings\SMOHAPATRA1\Application Data\Microsoft\Word\~WRL0009.tmp" Sat 21 Jun 2008 20,992 ...H. --- "C:\Documents and Settings\SMOHAPATRA1\Application Data\Microsoft\Word\~WRL0010.tmp" Mon 14 Jul 2008 8,246 A..H. --- "C:\Documents and Settings\SMOHAPATRA1\Application Data\Microsoft\Office\Shortcut Bar\Off4s.tmp" Mon 14 Jul 2008 8,246 A..H. --- "C:\Documents and Settings\SMOHAPATRA1\Application Data\Microsoft\Office\Shortcut Bar\Off4h.tmp" Mon 21 Jul 2008 7,318 A..H. --- "C:\Documents and Settings\SMOHAPATRA1\Application Data\Microsoft\Office\Shortcut Bar\Off4.tmp" [b]Finished![/b]