SDFix: Version 1.201 Run by Administrator on Fri 07/04/2008 at 12:46 AM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Checking Services :
Restoring Default Security Values
Restoring Default Hosts File
Rebooting
Checking Files :
Trojan Files Found:
C:\WINDOWS\Temp\ed47fa.$ - Deleted
Note - Files associated with the MBR Rootkit have been found on this system, to check the PC use the MBR Rootkit Detector by Gmer or CureIt by Dr.WebCould Not Remove C:\WINDOWS\Temp\bca4e2da.$$$
Could Not Remove C:\WINDOWS\Temp\fa56d7ec.$$$
Folder C:\WINDOWS\system32\aqVreo01 - Removed
Folder C:\WINDOWS\system32\vntiho01 - Removed
Removing Temp Files
ADS Check :
Final Check :
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-07-04 01:09:54
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
Remaining Files :
C:\WINDOWS\Temp\bca4e2da.$$$ Found
C:\WINDOWS\Temp\fa56d7ec.$$$ Found
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes :
Sun 13 Apr 2008 1,695,232 ..SH. --- "C:\Program Files\Messenger\msmsgs.exe"
Sun 13 Apr 2008 60,416 A.SH. --- "C:\Program Files\Outlook Express\msimn.exe"
Sun 13 Apr 2008 4,639 A.SH. --- "C:\Program Files\Windows Media Player\mplayer2.exe"
Wed 22 Sep 2004 73,728 A.SH. --- "C:\Program Files\Windows Media Player\wmplayer.exe"
Sun 13 Apr 2008 0 A..H. --- "C:\WINDOWS\system32\BIT748.tmp"
Mon 12 Sep 2005 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Mon 23 Jun 2008 37,888 ...H. --- "C:\Documents and Settings\Michael\My Documents\~WRL0005.tmp"
Fri 20 Jun 2008 32,768 ...H. --- "C:\Documents and Settings\Michael\My Documents\~WRL0471.tmp"
Mon 23 Jun 2008 36,352 ...H. --- "C:\Documents and Settings\Michael\My Documents\~WRL0978.tmp"
Wed 25 Jun 2008 33,792 ...H. --- "C:\Documents and Settings\Michael\My Documents\~WRL2477.tmp"
Fri 20 Jun 2008 35,328 ...H. --- "C:\Documents and Settings\Michael\My Documents\~WRL2765.tmp"
Fri 20 Jun 2008 34,304 ...H. --- "C:\Documents and Settings\Michael\My Documents\~WRL2787.tmp"
Mon 23 Jun 2008 36,352 ...H. --- "C:\Documents and Settings\Michael\My Documents\~WRL3597.tmp"
Tue 7 Feb 2006 299,008 A..H. --- "C:\Program Files\Canon\MP Navigator 3.0\Maint.exe"
Mon 19 Dec 2005 61,440 A..H. --- "C:\Program Files\Canon\MP Navigator 3.0\uinstrsc.dll"
Tue 24 Apr 2007 229,888 ...H. --- "C:\Documents and Settings\Meredith\Application Data\Microsoft\Word\~WRL0004.tmp"
Tue 24 Apr 2007 239,104 ...H. --- "C:\Documents and Settings\Meredith\Application Data\Microsoft\Word\~WRL0219.tmp"
Tue 24 Apr 2007 234,496 ...H. --- "C:\Documents and Settings\Meredith\Application Data\Microsoft\Word\~WRL0220.tmp"
Tue 24 Apr 2007 237,568 ...H. --- "C:\Documents and Settings\Meredith\Application Data\Microsoft\Word\~WRL0334.tmp"
Tue 24 Apr 2007 235,008 ...H. --- "C:\Documents and Settings\Meredith\Application Data\Microsoft\Word\~WRL0359.tmp"
Tue 24 Apr 2007 237,568 ...H. --- "C:\Documents and Settings\Meredith\Application Data\Microsoft\Word\~WRL0708.tmp"
Tue 24 Apr 2007 231,424 ...H. --- "C:\Documents and Settings\Meredith\Application Data\Microsoft\Word\~WRL1021.tmp"
Tue 24 Apr 2007 239,104 ...H. --- "C:\Documents and Settings\Meredith\Application Data\Microsoft\Word\~WRL1562.tmp"
Tue 24 Apr 2007 234,496 ...H. --- "C:\Documents and Settings\Meredith\Application Data\Microsoft\Word\~WRL1935.tmp"
Tue 24 Apr 2007 235,008 ...H. --- "C:\Documents and Settings\Meredith\Application Data\Microsoft\Word\~WRL2116.tmp"
Tue 24 Apr 2007 231,424 ...H. --- "C:\Documents and Settings\Meredith\Application Data\Microsoft\Word\~WRL2518.tmp"
Tue 24 Apr 2007 235,008 ...H. --- "C:\Documents and Settings\Meredith\Application Data\Microsoft\Word\~WRL3246.tmp"
Tue 24 Apr 2007 233,472 ...H. --- "C:\Documents and Settings\Meredith\Application Data\Microsoft\Word\~WRL3358.tmp"
Tue 24 Apr 2007 237,056 ...H. --- "C:\Documents and Settings\Meredith\Application Data\Microsoft\Word\~WRL3501.tmp"
Wed 2 Feb 2005 30,720 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL0003.tmp"
Fri 11 Mar 2005 179,200 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL0004.tmp"
Mon 25 Jun 2007 245,760 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL0005.tmp"
Fri 20 Jun 2008 36,352 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL0006.tmp"
Sun 13 Mar 2005 22,016 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL0022.tmp"
Mon 9 Jul 2007 269,312 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL0037.tmp"
Sun 13 Mar 2005 40,448 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL0094.tmp"
Mon 9 Jul 2007 264,704 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL0179.tmp"
Thu 28 Jun 2007 263,680 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL0210.tmp"
Sun 15 Jul 2007 275,456 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL0259.tmp"
Fri 11 Mar 2005 179,712 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL0353.tmp"
Mon 25 Jun 2007 245,760 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL0383.tmp"
Tue 26 Jun 2007 256,000 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL0384.tmp"
Wed 27 Jun 2007 260,096 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL0414.tmp"
Mon 25 Jun 2007 246,272 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL0417.tmp"
Mon 9 Jul 2007 278,016 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL0515.tmp"
Mon 9 Jul 2007 266,752 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL0532.tmp"
Fri 20 Jun 2008 35,328 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL0549.tmp"
Mon 9 Jul 2007 265,728 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL0619.tmp"
Mon 9 Jul 2007 268,288 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL0630.tmp"
Sat 12 Mar 2005 178,688 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL0682.tmp"
Tue 26 Jun 2007 256,000 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL0772.tmp"
Mon 9 Jul 2007 268,800 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL1010.tmp"
Sat 8 Sep 2007 32,768 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL1030.tmp"
Mon 9 Jul 2007 272,896 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL1055.tmp"
Mon 9 Jul 2007 275,968 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL1064.tmp"
Tue 26 Jun 2007 253,952 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL1078.tmp"
Sun 15 Jul 2007 279,552 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL1161.tmp"
Mon 9 Jul 2007 274,432 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL1182.tmp"
Fri 20 Jun 2008 34,816 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL1200.tmp"
Sun 15 Jul 2007 278,528 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL1343.tmp"
Sat 8 Sep 2007 34,304 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL1450.tmp"
Sun 13 Mar 2005 43,008 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL1472.tmp"
Sun 15 Jul 2007 280,576 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL1482.tmp"
Fri 11 Mar 2005 179,712 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL1675.tmp"
Mon 9 Jul 2007 265,728 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL1866.tmp"
Tue 26 Jun 2007 255,488 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL1889.tmp"
Mon 9 Jul 2007 271,872 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL1907.tmp"
Sun 13 Mar 2005 46,592 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL1910.tmp"
Sun 15 Jul 2007 276,480 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL1977.tmp"
Tue 26 Jun 2007 253,440 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL2005.tmp"
Fri 29 Jun 2007 267,264 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL2230.tmp"
Thu 28 Jun 2007 264,704 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL2327.tmp"
Mon 9 Jul 2007 271,872 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL2381.tmp"
Sat 12 Mar 2005 182,272 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL2416.tmp"
Mon 9 Jul 2007 268,288 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL2562.tmp"
Mon 9 Jul 2007 271,360 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL2593.tmp"
Tue 26 Jun 2007 257,536 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL2640.tmp"
Sun 13 Mar 2005 19,968 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL2686.tmp"
Sun 13 Mar 2005 45,056 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL2900.tmp"
Thu 28 Jun 2007 266,240 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL2915.tmp"
Mon 9 Jul 2007 276,992 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL2940.tmp"
Sun 9 Sep 2007 45,568 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL3063.tmp"
Mon 9 Jul 2007 268,288 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL3077.tmp"
Sun 13 Mar 2005 35,328 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL3081.tmp"
Sun 13 Mar 2005 22,528 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL3171.tmp"
Sun 15 Jul 2007 274,432 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL3185.tmp"
Fri 11 Mar 2005 178,688 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL3206.tmp"
Mon 9 Jul 2007 265,728 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL3227.tmp"
Mon 9 Jul 2007 267,264 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL3248.tmp"
Thu 28 Jun 2007 264,704 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL3270.tmp"
Tue 26 Jun 2007 254,464 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL3273.tmp"
Mon 9 Jul 2007 274,944 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL3280.tmp"
Sun 15 Jul 2007 276,480 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL3376.tmp"
Fri 11 Mar 2005 180,224 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL3390.tmp"
Mon 9 Jul 2007 268,288 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL3446.tmp"
Sun 15 Jul 2007 283,648 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL3501.tmp"
Fri 29 Jun 2007 266,752 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL3547.tmp"
Fri 20 Jun 2008 35,840 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL3570.tmp"
Sun 13 Mar 2005 39,424 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL3630.tmp"
Sun 15 Jul 2007 275,968 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL3674.tmp"
Thu 28 Jun 2007 263,680 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL3750.tmp"
Sat 12 Mar 2005 179,200 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL3808.tmp"
Mon 9 Jul 2007 268,288 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL3818.tmp"
Tue 26 Jun 2007 257,536 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL3959.tmp"
Sat 8 Sep 2007 34,304 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL4063.tmp"
Wed 2 Feb 2005 29,696 ...H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Word\~WRL4065.tmp"
Mon 12 Feb 2007 3,096,576 A..H. --- "C:\Documents and Settings\Michael\Application Data\U3\temp\Launchpad Removal.exe"
Mon 2 Jun 2008 11,638 A..H. --- "C:\Documents and Settings\Michael\Application Data\Microsoft\Office\Shortcut Bar\Off622.tmp"
Finished!