Notices
The Basement Non-Honda/Acura discussion. Content should be tasteful and "primetime" safe.

SDFix

Thread Tools
 
Old Nov 5, 2007 | 04:05 PM
  #1  
98CoupeV6's Avatar
98CoupeV6
Thread Starter
lots and lots of fail
 
Joined: Dec 1999
Posts: 23,004
Likes: 1
From: Deeeeeeeeeeeeeeetroit
Default SDFix

Is the greatest program in the history of the world. Cleaned up my virus problems and found a couple I didn't know about

Direct DL link: http://downloads.andymanchesta.com/R...ools/SDFix.exe

Download
SDFix
and save it to your Desktop.

Double click SDFix.exe and choose Install to extract it to its
own folder on the Desktop. Please then reboot your computer in Safe
Mode by doing the following :
Restart your computer
After hearing your computer beep once during startup, but before the
Windows icon appears, tap the F8 key continually;
Instead of Windows loading as normal, the Advanced Options Menu should
appear;
Select the first option, to run Windows in Safe Mode, then press
Enter.
Choose your usual account.
Open the extracted SDFix folder and double click RunThis.bat to
start the script.
Type Y to begin the cleanup process.
It will remove any Trojan Services or Registry Entries found then prompt
you to press any key to Reboot.
Press any Key and it will restart the PC.
When the PC restarts the Fixtool will run again and complete the removal
process then display Finished, press any key to end the script and
load your desktop icons.
Once the desktop icons load the SDFix report will open on screen and
also save into the SDFix folder as Report.txt.
Finally copy and paste the contents of the results file
Report.txt with a new HijackThis log

This was my log:

SDFix: Version 1.113

Run by Christopher Hall on Mon 11/05/2007 at 07:41 PM

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:


Restoring Windows Registry Values
Restoring Windows Default Hosts File
Restoring Default HomePage Value
Restoring Default Desktop Components Value

Rebooting...


Normal Mode:
Checking Files:

Trojan Files Found:

C:\Documents and Settings\Christopher Hall\Favorites\Error Cleaner.url - Deleted
C:\Documents and Settings\Christopher Hall\Favorites\Privacy Protector.url - Deleted
C:\Documents and Settings\Christopher Hall\Favorites\Spyware&Malware Protection.url - Deleted
C:\WINDOWS\dat.txt - Deleted
C:\WINDOWS\msmdev.dll - Deleted
C:\WINDOWS\msmhost.dll - Deleted
C:\WINDOWS\rs.txt - Deleted
C:\WINDOWS\search_res.txt - Deleted



Removing Temp Files...

ADS Check:

C:\WINDOWS
No streams found.

C:\WINDOWS\system32
No streams found.

C:\WINDOWS\system32\svchost.exe
No streams found.

C:\WINDOWS\system32\ntoskrnl.exe
No streams found.



Final Check:

catchme 0.3.1253 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-05 19:54:37
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden services & system hive ...

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\sptd\Cfg]
"s1"=dword:8f16276d
"s2"=dword:6fe559fc
"h0"=dword:00000001

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:48,55,18,58,6d,ef,16,05,18,36,14,ea,44 ,e5,61,da,96,47,2f,90,55,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\s ptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:48,55,18,58,6d,ef,16,05,18,36,14,ea,44 ,e5,61,da,96,47,2f,90,55,..

scanning hidden registry entries ...

source file error: C:\Documents and Settings\Christopher Hall\ntuser.dat
scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services:
------------------



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\sharedaccess\parameters\firewallpolicy\standard profile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\syste m32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:MSN Messenger 7.5"
"C:\\Program Files\\Sony\\vaio media integrated server\\Platform\\SV_Httpd.exe"="C:\\Program Files\\Sony\\vaio media integrated server\\Platform\\SV_Httpd.exe:*:enabled:SV_Httpd"
"C:\\Program Files\\Sony\\vaio media integrated server\\Platform\\UPnPFramework.exe"="C:\\Program Files\\Sony\\vaio media integrated server\\Platform\\UPnPFramework.exe:*:enabled:UPnP Framework"
"C:\\Chain\\creation.exe"="C:\\Chain\\creation.exe :*:Enabled:2AM Creation game engine"
"C:\\Program Files\\Common Files\\AOL\\1145844844\\ee\\aim6.exe"="C:\\Program Files\\Common Files\\AOL\\1145844844\\ee\\aim6.exe:*:Enabled:AIM "
"C:\\Program Files\\Sony\\click to dvd 2\\CtoDvd.exe"="C:\\Program Files\\Sony\\click to dvd 2\\CtoDvd.exe:*:Enabled:Click to DVD"
"C:\\Program Files\\MCEWeather\\cbServer\\cbServer.exe"="C:\\Pr ogram Files\\MCEWeather\\cbServer\\cbServer.exe:*:Enable d:cbServer"
"C:\\Program Files\\utorrent\\utorrent.exe"="C:\\Program Files\\utorrent\\utorrent.exe:*:Enabled:ęTorrent"
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader"
"C:\\Program Files\\Common Files\\AOL\\1145844844\\ee\\aolsoftware.exe"="C:\\ Program Files\\Common Files\\AOL\\1145844844\\ee\\aolsoftware.exe:*:Enab led:AOL Services"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\ \Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Ena bled:Yahoo! Messenger"
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Progra m Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Ya hoo! FT Server"
"C:\\Program Files\\Sony\\VAIO Media 4.0\\Vc.exe"="C:\\Program Files\\Sony\\VAIO Media 4.0\\Vc.exe:*isabled:[VAIO Media] VAIO Media"
"C:\\Documents and Settings\\Christopher Hall\\Application Data\\U3\\0000060510092335\\0DE4F643-C398-46ec-9339-2362F2311932\\Exec\\skype.exe"="C:\\Documents and Settings\\Christopher Hall\\Application Data\\U3\\0000060510092335\\0DE4F643-C398-46ec-9339-2362F2311932\\Exec\\skype.exe:*:Enabled:Skype"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"c:\\windows\\system32\\opnsqr.exe"="c:\\windows\\ system32\\opnsqr.exe:*:Enabledpnsqr.exe"
"C:\\Program Files\\AIM6\\aim6.exe"="C:\\Program Files\\AIM6\\aim6.exe:*:Enabled:AIM"
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"="C:\\Program Files\\Grisoft\\AVG7\\avginet.exe:*:Enabled:avgine t.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe:*:Enabled:avgam svr.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe:*:Enabled:avgcc.ex e"
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe:*:Enabled:avgemc. exe"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\sharedaccess\parameters\firewallpolicy\domainpr ofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\syste m32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:MSN Messenger 7.5"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

Remaining Files:
---------------

File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes:

Sun 23 Apr 2006 403 A..H. --- "C:\Documents and Settings\Christopher Hall\IPH.BAK"
Sun 23 Apr 2006 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Wed 10 Oct 2007 2,306 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv10.bak"
Sun 27 May 2007 2,306 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv11.bak"
Mon 27 Aug 2007 1,925 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv12.bak"
Wed 25 Jul 2007 3,830 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv13.bak"
Wed 24 Oct 2007 3,449 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv14.bak"
Wed 10 Oct 2007 3,830 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv15.bak"
Tue 25 Sep 2007 2,687 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv16.bak"
Tue 11 Sep 2007 2,306 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv17.bak"
Wed 24 Oct 2007 4,592 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv18.bak"
Sun 11 Mar 2007 1,163 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv19.bak"
Tue 13 Jun 2006 44,544 ...H. --- "C:\Documents and Settings\Christopher Hall\Desktop\~WRL0005.tmp"
Tue 13 Jun 2006 87,552 ...H. --- "C:\Documents and Settings\Christopher Hall\Desktop\~WRL0350.tmp"
Wed 29 Sep 2004 15,360 A..HR --- "C:\WINDOWS\system32\drivers\NetMotCM.sys"
Tue 6 Mar 2007 63,668 A.SH. --- "C:\Documents and Settings\All Users\Documents\Recorded TV\MSDVRMM_485380644_2686976_444765.tmp"
Sun 4 Feb 2007 31,862 A.SH. --- "C:\Documents and Settings\All Users\Documents\Recorded TV\MSDVRMM_485380644_7602176_45915.tmp"
Mon 4 Jun 2007 586 A..H. --- "C:\Program Files\Common Files\AOL\IPHSend\IPH.BAK"

Finished!
Reply
Old Nov 5, 2007 | 05:30 PM
  #2  
k3ifers's Avatar
k3ifers
k three ifers
 
Joined: Jun 2002
Posts: 42,568
Likes: 4
From: Buffalo, NY
Default

so what happened?
Reply
Old Nov 5, 2007 | 05:34 PM
  #3  
Misa's Avatar
Misa
Pic Whore
 
Joined: Jul 2004
Posts: 22,224
Likes: 1
From: NJ
Default

found nothing.
Reply
Old Nov 5, 2007 | 05:38 PM
  #4  
98CoupeV6's Avatar
98CoupeV6
Thread Starter
lots and lots of fail
 
Joined: Dec 1999
Posts: 23,004
Likes: 1
From: Deeeeeeeeeeeeeeetroit
Default

Originally Posted by Jani 5
found nothing.
you did it?

Originally Posted by k3ifers
so what happened?
I had a really nasty virus that screwed up my active desktop and none of my virus programs (avast, AVG, norton) could do fix that. They removed the virus but this program was the only one that restored my desktop. Plus my PC is running like 100x faster.
Reply
Old Nov 5, 2007 | 05:39 PM
  #5  
Misa's Avatar
Misa
Pic Whore
 
Joined: Jul 2004
Posts: 22,224
Likes: 1
From: NJ
Default

Originally Posted by 98CoupeV6
you did it?
yup.
Reply




All times are GMT -8. The time now is 05:43 AM.