SDFix: Version 1.137 Run by [removed] on Wed 02/06/2008 at 02:01 PM Microsoft Windows XP [Version 5.1.2600] Running From: C:\SDFix Safe Mode: Checking Services: Name: CcEvtSvc msupdate Path: %SystemRoot%\System32\CcEvtSvc.exe -k netsvcs c:\windows\system32\mssrv32.exe CcEvtSvc - Deleted msupdate - Deleted Infected ip6fw.sys Found! ip6fw.sys File Locations: "C:\WINDOWS\system32\dllcache\ip6fw.sys" 29056 08/04/2004 06:00 AM "C:\WINDOWS\system32\drivers\ip6fw.sys" 29056 08/04/2004 06:00 AM Infected File Listed Below: C:\WINDOWS\system32\drivers\ip6fw.sys File copied to Backups Folder Attempting to replace ip6fw.sys with original version... Original ip6fw.sys Restored Restoring Windows Registry Values Restoring Windows Default Hosts File Restoring Default Desktop Wallpaper Rebooting... Service asc3550p - Deleted after Reboot Service Ywe34 - Deleted after Reboot Normal Mode: Checking Files: Trojan Files Found: C:\WINDOWS\system32\expand.dll - Deleted C:\WINDOWS\system32\drivers\Wbu31.sys - Deleted C:\WINDOWS\system32\drivers\Xtfi41.sys - Deleted C:\WINDOWS\system32\drivers\Ywe34.sys - Deleted C:\WINDOWS\SYSTEM32\DLLGH8~1.EXE - Deleted C:\WINDOWS\SYSTEM32\203915~1.DLL - Deleted C:\WINDOWS\system32\service\dllp.txt - Deleted C:\WINDOWS\system32\2_exception.nls - Deleted C:\WINDOWS\system32\dllgh8jkd1q1.exe - Deleted C:\WINDOWS\system32\dllgh8jkd1q2.exe - Deleted C:\WINDOWS\system32\dllgh8jkd1q5.exe - Deleted C:\WINDOWS\system32\dllgh8jkd1q6.exe - Deleted C:\WINDOWS\system32\dllgh8jkd1q7.exe - Deleted C:\WINDOWS\system32\dllgh8jkd1q8.exe - Deleted C:\WINDOWS\system32\m1ax1d12132116143v.exe - Deleted C:\WINDOWS\system32\m1ax1d1213216143v.exe - Deleted C:\WINDOWS\system32\n2ewma1xxsv234.exe - Deleted C:\WINDOWS\system32\newmaxxsv234.exe - Deleted C:\WINDOWS\system32\vedxg4am1et2.exe - Deleted C:\WINDOWS\system32\vedxg6ame4.exe - Deleted C:\WINDOWS\system32\vedxga1me4t1.exe - Deleted C:\Documents and Settings\MAPepin\Application Data\Install.dat - Deleted C:\WINDOWS\system32\CcEvtSvc.exe - Deleted C:\WINDOWS\system32\form.txt - Deleted C:\WINDOWS\system32\info.txt - Deleted C:\WINDOWS\system32\kernelwind64.exe - Deleted C:\WINDOWS\system32\kr_done1 - Deleted C:\WINDOWS\system32\lich.dat - Deleted C:\WINDOWS\system32\mssrv32.exe - Deleted C:\WINDOWS\system32\svcp.csv - Deleted C:\WINDOWS\system32\vx.tll - Deleted C:\WINDOWS\system32\winsub.xml - Deleted C:\WINDOWS\xpupdate.exe - Deleted C:\WINDOWS\system32\drivers\symavc32.sys - Deleted Could Not Remove C:\WINDOWS\SYSTEM32\231674~1.DAT Folder C:\WINDOWS\system32\service - Removed Removing Temp Files... ADS Check: Final Check: catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-02-06 14:04:08 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden services & system hive ... scanning hidden registry entries ... scanning hidden files ... scan completed successfully hidden processes: 0 hidden services: 0 hidden files: 0 Remaining Services: ------------------ CcEvtSvc Authorized Application Key Export: [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] "C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"="C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe:*:Enabled:McAfee Network Agent" "C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger" "C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server" "C:\\WINDOWS\\system32\\mmc.exe"="C:\\WINDOWS\\system32\\mmc.exe:*:Enabled:Microsoft Management Console" "C:\\WINDOWS\\system32\\mmdssvc.exe"="C:\\WINDOWS\\system32\\mmdssvc.exe:*:Enabled:mmdssvc" "C:\\WINDOWS\\system32\\sessmgr.exe"="C:\\WINDOWS\\system32\\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019" "C:\\WINDOWS\\system32\\runtime.exe"="C:\\WINDOWS\\system32\\runtime.exe:*:Disabled:runtime.exe" "C:\\Documents and Settings\\MAPepin\\tmp.exe"="C:\\Documents and Settings\\MAPepin\\tmp.exe:*:Disabled:runtime.exe" "C:\\Documents and Settings\\MAPepin\\Desktop\\tmp.exe"="C:\\Documents and Settings\\MAPepin\\Desktop\\tmp.exe:*:Disabled:runtime.exe" "C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"="C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE:*:Disabled:Internet Explorer" [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" Remaining Files: --------------- C:\WINDOWS\SYSTEM32\231674~1.DAT Found File Backups: - C:\SDFix\backups\backups.zip Files with Hidden Attributes: Fri 1 Feb 2008 38,400 ..SHR --- "C:\WINDOWS\system32\6to4svcq.exe" Thu 31 Jan 2008 17,920 A.SH. --- "C:\WINDOWS\system32\accessw.dll" Wed 6 Feb 2008 38,400 ..SHR --- "C:\WINDOWS\system32\accesswr.exe" Thu 17 Jan 2008 20,487 A.SHR --- "C:\Program Files\McAfee\MQC\MRU.bak" Thu 17 Jan 2008 211 A.SHR --- "C:\Program Files\McAfee\MQC\qcconf.bak" Sat 19 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\0a67b6c406b1d7e0f5c1e6f6d44a3f6e\BIT4.tmp" Sat 19 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\26924cbc8132a10b438ce6e2b49d4652\BIT2.tmp" Sat 19 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\2769b111678c52099a3b3123b12f2325\BIT6.tmp" Fri 25 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\585dc2612ebcefc90e7dee4c276ee95e\BIT1.tmp" Sat 19 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\6b636582f273e0b4cae6f62415c52d81\BIT8.tmp" Wed 6 Feb 2008 8,340,783 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\7a5a959f7dd6b76d854fc3c066993fad\BIT9.tmp" Sat 19 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\b69c46c5109d0f8b0dee9fab84906813\BIT5.tmp" Sat 19 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\d77b9b5b8fed23dd91f50d167cce60d3\BIT7.tmp" Sat 19 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\fa6c916bb150f8a929e7a4ffdfbc120f\BIT3.tmp" Mon 4 Feb 2008 36,864 ...H. --- "C:\Documents and Settings\MAPepin\Application Data\Microsoft\Templates\~WRL0002.tmp" Finished!