SDFix Report_Rapport Report
PSKELLEY,
Thanks for helping us with this nasty business. Your recommendations were clear and easy to follow. Reports to follow.
Please let me know what (if anything) to do next. It appears we are still getting unrequested web pages, even when getting online to pursue this thread...
Thank You!
SDFix: Version 1.112
Run by Gentle Wife on Fri 10/26/2007 at 11:23 PM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Name:
cmdService
runtime
ImagePath:
C:\WINDOWS\R2VudGxlIFdpZmU\command.exe
\??\C:\WINDOWS\System32\drivers\runtime.sys
cmdService - Deleted
runtime - Deleted
Killing PID 936 'printer.exe'
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Resetting AppInit_DLLs value
Rebooting...
Service runtime2 - Deleted after Reboot
Normal Mode:
Checking Files:
Trojan Files Found:
"C:\WINDOWS\R2VudGxlIFdpZmU\asappsrv.dll" - Deleted
C:\WINDOWS\R2VudGxlIFdpZmU\lZpRx3U5KIxDtAo.vbs - Deleted
C:\WINDOWS\retadpu1000106.exe.tmp - Deleted
C:\Program Files\Common Files\Yazzle1122OinAdmin.exe - Deleted
C:\Program Files\Common Files\Yazzle1122OinUninstaller.exe - Deleted
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\autorun.exe - Deleted
C:\Documents and Settings\Gentle Wife\Start Menu\Programs\Startup\system.exe - Deleted
C:\DOCUME~1\GENTLE~1\LOCALS~1\Temp\uninstall.exe - Deleted
C:\WINDOWS\avp.exe - Deleted
C:\WINDOWS\b104.exe - Deleted
C:\WINDOWS\b122.exe - Deleted
C:\WINDOWS\b128.exe - Deleted
C:\WINDOWS\b138.exe - Deleted
C:\WINDOWS\b147.exe - Deleted
C:\WINDOWS\mgrs.exe - Deleted
C:\WINDOWS\system32\1_exception.nls - Deleted
C:\WINDOWS\system32\atmtd.dll - Deleted
C:\WINDOWS\system32\atmtd.dll._ - Deleted
C:\WINDOWS\system32\printer.exe - Deleted
C:\WINDOWS\system32\vtr.dll - Deleted
C:\WINDOWS\system32\winavxx.exe - Deleted
C:\WINDOWS\Temp\startdrv.exe - Deleted
C:\WINDOWS\uninstall_nmon.vbs - Deleted
C:\WINDOWS\system32\drivers\runtime.sys - Deleted
C:\WINDOWS\system32\drivers\runtime2.sys - Deleted
Could Not Remove C:\WINDOWS\system32\sulimo.dat
Folder C:\Program Files\Temporary - Removed
Removing Temp Files...
ADS Check:
C:\WINDOWS
No streams found.
C:\WINDOWS\system32
No streams found.
C:\WINDOWS\system32\svchost.exe
No streams found.
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.
Final Check:
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled

xpsp2res.dll,-22019"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
"C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Enabled:AOL"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\Adobe\\Adobe Version Cue CS2\\bin\\VersionCueCS2.exe"="C:\\Program Files\\Adobe\\Adobe Version Cue CS2\\bin\\VersionCueCS2.exe:*:Enabled:Adobe Version Cue CS2"
"C:\\WINDOWS\\system32\\pyprgjhf.exe"="C:\\WINDOWS\\system32\\pyp"
"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"="C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE:*

isabled:Internet Explorer"
"%windir%\\system32\\winav.exe"="%windir%\\system32\\winav.exe:*:Enabled

xpsp2res.dll,-22019"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled

xpsp2res.dll,-22019"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
"C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Enabled:AOL"
"%windir%\\system32\\winav.exe"="%windir%\\system32\\winav.exe:*:Enabled

xpsp2res.dll,-22019"
Remaining Files:
---------------
C:\WINDOWS\system32\sulimo.dat Found
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes:
Wed 1 Sep 2004 54,384 A..H. --- "C:\Program Files\America Online 9.0\aolphx.exe"
Wed 1 Sep 2004 156,784 A..H. --- "C:\Program Files\America Online 9.0\aoltray.exe"
Wed 1 Sep 2004 31,344 A..H. --- "C:\Program Files\America Online 9.0\RBM.exe"
Tue 18 Sep 2007 88 ..SHR --- "C:\WINDOWS\system32\3C439DD1A0.sys"
Sun 19 Aug 2007 56 ..SHR --- "C:\WINDOWS\system32\A0D19D433C.sys"
Wed 10 Oct 2007 6,465 ..SH. --- "C:\WINDOWS\system32\ayadd.bak1"
Mon 15 Oct 2007 6,935 ..SH. --- "C:\WINDOWS\system32\ayadd.bak2"
Fri 12 Oct 2007 6,465 ..SH. --- "C:\WINDOWS\system32\cdeeg.bak1"
Tue 2 Oct 2007 6,465 ..SH. --- "C:\WINDOWS\system32\ehhkj.bak1"
Sun 7 Oct 2007 6,465 ..SH. --- "C:\WINDOWS\system32\fgjlm.bak1"
Fri 12 Oct 2007 7,045 ..SH. --- "C:\WINDOWS\system32\fgjlm.bak2"
Tue 16 Oct 2007 411,670 ..SH. --- "C:\WINDOWS\system32\gjkmp.bak1"
Fri 26 Oct 2007 453,950 ..SH. --- "C:\WINDOWS\system32\gjkmp.bak2"
Thu 11 Oct 2007 6,505 ..SH. --- "C:\WINDOWS\system32\gjllm.bak1"
Tue 18 Sep 2007 4,184 A.SH. --- "C:\WINDOWS\system32\KGyGaAvL.sys"
Sun 7 Oct 2007 6,465 ..SH. --- "C:\WINDOWS\system32\kjkmp.bak1"
Thu 11 Oct 2007 6,465 ..SH. --- "C:\WINDOWS\system32\kjllm.bak1"
Sat 6 Oct 2007 6,465 ..SH. --- "C:\WINDOWS\system32\llnmp.bak1"
Thu 27 Sep 2007 6,448 ..SH. --- "C:\WINDOWS\system32\mpqss.bak1"
Sun 30 Sep 2007 2,107,505 ..SH. --- "C:\WINDOWS\system32\mpqss.bak2"
Sun 7 Oct 2007 6,465 ..SH. --- "C:\WINDOWS\system32\onnmp.bak1"
Sun 7 Oct 2007 6,465 ..SH. --- "C:\WINDOWS\system32\oqstv.bak1"
Mon 8 Oct 2007 6,465 ..SH. --- "C:\WINDOWS\system32\rtstv.bak1"
Mon 8 Oct 2007 6,618 ..SH. --- "C:\WINDOWS\system32\rtstv.bak2"
Fri 5 Oct 2007 6,465 ..SH. --- "C:\WINDOWS\system32\rtvwa.bak1"
Mon 15 Oct 2007 6,993 ..SH. --- "C:\WINDOWS\system32\rtvwa.bak2"
Tue 2 Oct 2007 6,465 ..SH. --- "C:\WINDOWS\system32\sstwa.bak1"
Thu 4 Oct 2007 6,465 ..SH. --- "C:\WINDOWS\system32\tstwa.bak1"
Sat 6 Oct 2007 1,977,552 ..SH. --- "C:\WINDOWS\system32\tstwa.bak2"
Sat 13 Oct 2007 6,465 ..SH. --- "C:\WINDOWS\system32\vvvwa.bak1"
Tue 9 Oct 2007 6,465 ..SH. --- "C:\WINDOWS\system32\vyadd.bak1"
Wed 3 Oct 2007 6,465 ..SH. --- "C:\WINDOWS\system32\vycdd.bak1"
Wed 10 Oct 2007 6,465 ..SH. --- "C:\WINDOWS\system32\ybadd.bak1"
Mon 15 Oct 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\8361ae28fcfac79271825a6b2935fdb6\BITA.tmp"
Thu 19 Jul 2007 8 A..H. --- "C:\Documents and Settings\Gentle Wife\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u1\lock.tmp"
Thu 19 Jul 2007 8 A..H. --- "C:\Documents and Settings\Gentle Wife\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u2\lock.tmp"
Thu 19 Jul 2007 8 A..H. --- "C:\Documents and Settings\Gentle Wife\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u3\lock.tmp"
Wed 25 Jul 2007 8 A..H. --- "C:\Documents and Settings\Gentle Wife\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u4\lock.tmp"
Thu 19 Jul 2007 8 A..H. --- "C:\Documents and Settings\Gentle Husband\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u1\lock.tmp"
Thu 19 Jul 2007 8 A..H. --- "C:\Documents and Settings\Gentle Husband\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u2\lock.tmp"
Thu 19 Jul 2007 8 A..H. --- "C:\Documents and Settings\Gentle Husband\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u3\lock.tmp"
Thu 19 Jul 2007 8 A..H. --- "C:\Documents and Settings\Gentle Husband\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u4\lock.tmp"
Finished!
SmitFraudFix v2.242
Scan done at 23:06:37.31, Fri 10/26/2007
Run from C:\Documents and Settings\Gentle Wife\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode
»»»»»»»»»»»»»»»»»»»»»»»» Process
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\WINDOWS\system32\pyprgjhf.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\GEARSec.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton Ghost\Agent\VProSvc.exe
C:\Program Files\Adobe\Adobe Version Cue CS2\data\database\bin\mysqld-nt.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\avp.exe
C:\WINDOWS\mgrs.exe
C:\Program Files\Norton Ghost\Agent\GhostTray.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2J1.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe
C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\autorun.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\system32\wuauclt.exe
C:\DOCUME~1\GENTLE~1\LOCALS~1\Temp\hostagent.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\cmd.exe
»»»»»»»»»»»»»»»»»»»»»»»» hosts
hosts file corrupted !
192.168.200.3 download.microsoft.com
192.168.200.3 downloads.microsoft.com
192.168.200.3 go.microsoft.com
192.168.200.3 microsoft.com
192.168.200.3 msdn.microsoft.com
192.168.200.3 office.microsoft.com
192.168.200.3 support.microsoft.com
192.168.200.3 windowsupdate.microsoft.com
192.168.200.3
www.microsoft.com
192.168.200.3 pandasoftware.com
192.168.200.3
www.pandasoftware.com
»»»»»»»»»»»»»»»»»»»»»»»» C:\
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
C:\WINDOWS\avp.exe FOUND !
C:\WINDOWS\mgrs.exe FOUND !
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
C:\WINDOWS\system32\printer.exe FOUND !
C:\WINDOWS\system32\sulimo.dat FOUND !
C:\WINDOWS\system32\vtr???.dll FOUND !
C:\WINDOWS\system32\WinAvXX.exe FOUND !
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Gentle Wife
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Gentle Wife\Application Data
»»»»»»»»»»»»»»»»»»»»»»»» Start Menu
C:\DOCUME~1\GENTLE~1\STARTM~1\Programs\Startup\system.exe FOUND !
C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\autorun.exe FOUND !
»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\GENTLE~1\FAVORI~1
»»»»»»»»»»»»»»»»»»»»»»»» Desktop
»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys
»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="C:\\Program Files\\Common Files\\rtemehd.html"
"SubscribedURL"=""
"FriendlyName"=""
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\1]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\\WINDOWS\\system32\\sulimo.dat"
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""
»»»»»»»»»»»»»»»»»»»»»»»» Rustock
»»»»»»»»»»»»»»»»»»»»»»»» DNS
Description: Intel(R) PRO/100 VE Network Connection - Packet Scheduler Miniport
DNS Server Search Order: 216.68.4.10
DNS Server Search Order: 216.68.5.10
HKLM\SYSTEM\CCS\Services\Tcpip\..\{CE93C344-4BA3-4A1A-B87B-F29E97E6200F}: DhcpNameServer=216.68.4.10 216.68.5.10
HKLM\SYSTEM\CS1\Services\Tcpip\..\{CE93C344-4BA3-4A1A-B87B-F29E97E6200F}: DhcpNameServer=216.68.4.10 216.68.5.10
HKLM\SYSTEM\CS3\Services\Tcpip\..\{CE93C344-4BA3-4A1A-B87B-F29E97E6200F}: DhcpNameServer=216.68.4.10 216.68.5.10
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=216.68.4.10 216.68.5.10
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=216.68.4.10 216.68.5.10
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=216.68.4.10 216.68.5.10
»»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection
»»»»»»»»»»»»»»»»»»»»»»»» End