tiggly
Topic Starter
Thank you.
After a week of messing around and trying various downloads, none of them worked, my pc is finally clean of the annoying message after using SDfix and your help.
People creating these should be prosecuted for stealing our time.
Thanks again.
Log follows
SDFix: Version 1.132
Run by [removed] on Tue 01/29/2008 at 04:44 PM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting…
Normal Mode:
Checking Files:
Trojan Files Found:
C:\DOCUME~1\shauns\LOCALS~1\Temp\ac8zt2.dat - Deleted
C:\WINDOWS\dat.txt - Deleted
C:\WINDOWS\domnftwost.dll - Deleted
C:\WINDOWS\fvkwdrt.exe - Deleted
C:\WINDOWS\rs.txt - Deleted
C:\WINDOWS\search_res.txt - Deleted
Removing Temp Files…
ADS Check:
Final Check:
catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-29 16:46:52
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes …
scanning hidden services …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services:
——————
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
Remaining Files:
—————
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes:
Mon 21 Jan 2008 4,348 ..SH. — "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Sat 22 Dec 2007 5,903,928 A..H. — "C:\System Volume Information\_restore{93E92BF8-425F-45B5-AC23-65E4956FDD7D}\RP68\A0009642.exe"
Tue 8 Jan 2008 0 A..H. — "C:\Documents and Settings\Administrator\Local Settings\Temp\BIT5.tmp"
Tue 8 Jan 2008 85,946 A..H. — "C:\Documents and Settings\Administrator\Local Settings\Temp\BIT1.tmp"
Finished!
After a week of messing around and trying various downloads, none of them worked, my pc is finally clean of the annoying message after using SDfix and your help.
People creating these should be prosecuted for stealing our time.
Thanks again.
Log follows
SDFix: Version 1.132
Run by [removed] on Tue 01/29/2008 at 04:44 PM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting…
Normal Mode:
Checking Files:
Trojan Files Found:
C:\DOCUME~1\shauns\LOCALS~1\Temp\ac8zt2.dat - Deleted
C:\WINDOWS\dat.txt - Deleted
C:\WINDOWS\domnftwost.dll - Deleted
C:\WINDOWS\fvkwdrt.exe - Deleted
C:\WINDOWS\rs.txt - Deleted
C:\WINDOWS\search_res.txt - Deleted
Removing Temp Files…
ADS Check:
Final Check:
catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-29 16:46:52
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes …
scanning hidden services …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services:
——————
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
Remaining Files:
—————
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes:
Mon 21 Jan 2008 4,348 ..SH. — "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Sat 22 Dec 2007 5,903,928 A..H. — "C:\System Volume Information\_restore{93E92BF8-425F-45B5-AC23-65E4956FDD7D}\RP68\A0009642.exe"
Tue 8 Jan 2008 0 A..H. — "C:\Documents and Settings\Administrator\Local Settings\Temp\BIT5.tmp"
Tue 8 Jan 2008 85,946 A..H. — "C:\Documents and Settings\Administrator\Local Settings\Temp\BIT1.tmp"
Finished!