SDFix: Version 1.103
Run by Administrator on Sun 09/09/2007 at 11:16 AM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Name:
new_drv
NtmlSvc
ImagePath:
\??\C:\WINDOWS\new_drv.sys
%SystemRoot%\System32\svchost.exe -k netsvcs
new_drv - Deleted
NtmlSvc - Deleted
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting...
Service asc3550v - Deleted after Reboot
Service xpdx - Deleted after Reboot
Normal Mode:
Checking Files:
Trojan Files Found:
C:\WINDOWS\new_drv.sys - Deleted
C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.dll - Deleted
C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00002.dll - Deleted
C:\d.exe - Deleted
C:\WINDOWS\9129837.exe - Deleted
C:\WINDOWS\system32\cookie.dat - Deleted
C:\WINDOWS\system32\help.txt - Deleted
C:\WINDOWS\system32\mcacr.dll - Deleted
C:\WINDOWS\system32\ps.dat - Deleted
C:\WINDOWS\system32\win32.exe - Deleted
C:\WINDOWS\Temp\$_2341233.TMP - Deleted
C:\WINDOWS\Temp\$_2341234.TMP - Deleted
C:\WINDOWS\Temp\$b17a2e8.tmp - Deleted
C:\WINDOWS\system32\xpdx.sys - Deleted
C:\WINDOWS\system32\drivers\asc3550v.sys - Deleted
Folder C:\Temp\fse - Removed
Removing Temp Files...
ADS Check:
C:\WINDOWS
No streams found.
C:\WINDOWS\system32
No streams found.
C:\WINDOWS\system32\svchost.exe
No streams found.
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.
Final Check:
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled
xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\WINDOWS\\TEMP\\win68.tmp.exe"="C:\\WINDOWS\\TEMP\\win68.tmp.exe:*:Enabled:win68.tmp"
"C:\\WINDOWS\\system32\\VT100.EXE"="C:\\WINDOWS\\system32\\VT100.EXE:*:Enabled:VT100 Emulator"
"C:\\Program Files\\BitTornado\\btdownloadgui.exe"="C:\\Program Files\\BitTornado\\btdownloadgui.exe:*:Enabled:btdownloadgui"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled
xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
Remaining Files:
---------------
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes:
C:\System Volume Information\_restore{440C682E-13DA-47AD-A06D-E09F5E2B572E}\RP175\A0023925.EXE
C:\System Volume Information\_restore{440C682E-13DA-47AD-A06D-E09F5E2B572E}\RP177\A0024989.EXE
C:\WINDOWS\system32\1033v.exe
C:\WINDOWS\system32\3076d.exe
C:\WINDOWS\system32\aaaamonv.exe
C:\WINDOWS\system32\acctresr.exe
C:\WINDOWS\system32\alrsvcb.exe
C:\WINDOWS\system32\appwizh.exe
C:\WINDOWS\system32\ntoskrnl.exe
C:\WINDOWS\system32\hgjlm.tmp
Finished!
When ComboFix finished it said it was unable to open the log file, but there are 2 notepad files, they're probably not the log file but I'll post them anyway:
ComboFix 07-09-09.4 - "default" 2007-09-09 11:50:08.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.218 [GMT 1:00]
* Created a new restore point
.
Rootkit driver pe386 is present. ... attempting disinfection
Rootkit driver msguard is present. ... attempting disinfection
pe386 ...... driver unloaded successfully.
msguard ...... driver unloaded successfully.
ADS - ntoskrnl.exe: deleted 75046 bytes in 4 streams.
/wow section - STAGE 3
/wow section - STAGE 6
/wow section - STAGE 6A
/wow section - STAGE 7
/wow section - STAGE 8
/wow section - STAGE 11
/wow section - STAGE 15
/wow section - STAGE 16
/wow section - STAGE 25
And the other:
Files to delete:
C:\WINDOWS\system32\kprof
C:\WINDOWS\system32\koos.exe
C:\WINDOWS\system32\poof