14 Paź 2008, 21:34
15 Paź 2008, 06:21
15 Paź 2008, 11:57
16 Paź 2008, 21:55
16 Paź 2008, 23:14
17 Paź 2008, 00:15
17 Paź 2008, 05:47
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"=-
"SynTPEnh"=-
"IgfxTray"=-
"HotKeysCmds"=-
"Persistence"=-
"UpdateManager"=-
"dla"=-
"hpWirelessAssistant"=-
"WatchDog"=-
"AGRSMMSG"=-
Files to delete:
D:\instalki\BSINSTALLPL.exe
E:\instalki_2\BSINSTALLPL.exe
E:\RECYCLER\S-1-5-21-682003330-1957994488-725345543-1004
E:\shitki\bs\RunMSC.dll
E:\shitki\bs\Installer\BSINSTALLPL.exe
E:\stuff od Efci\BSINSTALLPL.exe
Folders to delete:
E:\RECYCLER\S-1-5-21-682003330-1957994488-725345543-1004
D:\System Volume Information\_restore{B7CDD19E-3E63-4E10-B2DD-BE098D36821E}\RP95
E:\System Volume Information\_restore{B7CDD19E-3E63-4E10-B2DD-BE098D36821E}\RP95
17 Paź 2008, 14:13
17 Paź 2008, 16:19
17 Paź 2008, 23:32
18 Paź 2008, 05:53
19 Paź 2008, 00:12
SDFix: Version 1.236
Run by Administrator on 2008-10-18 at 23:26
Microsoft Windows XP [Wersja 5.1.2600]
Running From: C:\SDFix
Checking Services :
Restoring Default Security Values
Restoring Default Hosts File
Rebooting
Checking Files :
No Trojan Files Found
Removing Temp Files
ADS Check :
Final Check :
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-18 23:30:08
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
Remaining Files :
Files with Hidden Attributes :
Mon 15 Sep 2008 1,562,960 A.SHR --- "C:\Program Files\SDHelper (Spybot - Search & Destroy)\SDHelper.dll"
Tue 16 Sep 2008 1,833,296 A.SHR --- "C:\Program Files\TeaTimer (Spybot - Search & Destroy)\TeaTimer.exe"
Fri 7 Sep 2007 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Tue 31 Jul 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Finished!
19 Paź 2008, 06:30