tarzan44
Topic Starter
Followed all of the step as outlined in the how to remove How To Remove: VIRUS ALERT (http://forums.whatthetech.com/How_To_Remove_VIRUS_ALERT_t93788.html)
1. Ran ERUNT
2. Ran ATF Cleaner»
3. Ran SDFix (both in safe mode and on start-up)
4. Ran Malwarebytes' Anti-Malware
5. Last step instructs to post report results… if you have any further tips please let me know. Thanks in advance for the help with this.
Report.txt…
SDFix: Version 1.235
Run by [removed] on 13/10/2008 at 22:53
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Checking Services :
Name :
tdssserv
Path :
\systemroot\system32\drivers\TDSSserv.sys
tdssserv - Deleted
Restoring Default Security Values
Restoring Default Hosts File
Rebooting
Checking Files :
Trojan Files Found:
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat - Contains Links to Malware Sites! - Deleted
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat - Contains Links to Malware Sites! - Deleted
C:\WINDOWS\system32\ssqOEWMf.dll - Deleted
C:\~VMD8.TMP - Deleted
C:\~VMD9.TMP - Deleted
C:\~VMDA.TMP - Deleted
C:\~VMDB.TMP - Deleted
C:\~VMDC.TMP - Deleted
C:\~VMDD.TMP - Deleted
C:\~VMDE.TMP - Deleted
C:\~VMDF.TMP - Deleted
C:\~VME0.TMP - Deleted
C:\Documents and Settings\H B Book Centre\Application Data\Adobe\Player.exe - Deleted
C:\Documents and Settings\H B Book Centre\Application Data\Adobe\Player.exe.bak - Deleted
C:\Documents and Settings\H B Book Centre\Desktop\Malware Defender.url - Deleted
C:\Documents and Settings\H B Book Centre\Favorites\Malware Defender.url - Deleted
C:\Documents and Settings\H B Book Centre\Desktop\Protect Your Privacy.url - Deleted
C:\Documents and Settings\H B Book Centre\Favorites\Protect Your Privacy.url - Deleted
C:\Documents and Settings\H B Book Centre\Desktop\System Error Fixer.url - Deleted
C:\Documents and Settings\H B Book Centre\Favorites\System Error Fixer.url - Deleted
C:\WINDOWS\system32\wini104552664.exe - Deleted
C:\WINDOWS\hkr32.asm - Deleted
C:\WINDOWS\mainms.vpi - Deleted
C:\WINDOWS\megavid.cdt - Deleted
C:\WINDOWS\muotr.so - Deleted
C:\WINDOWS\system32\brastk.exe - Deleted
C:\WINDOWS\Temp\removalfile.bat - Deleted
Folder C:\Temp\1cb - Removed
Removing Temp Files
ADS Check :
Final Check :
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-13 23:06:47
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden services & system hive …
scanning hidden registry entries …
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\VE LXi Expert 6\\Program\\App.exe"="C:\\Program Files\\VE LXi Expert 6\\Program\\App.exe:*:Enabled:FlexiSIGN-PRO"
"C:\\Program Files\\VE LXi Expert 6\\Program\\App2.exe"="C:\\Program Files\\VE LXi Expert 6\\Program\\App2.exe:*:Enabled:Production"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"="C:\\Program Files\\Real\\RealPlayer\\realplay.exe:*:Enabled:RealPlayer"
"C:\\Program Files\\Grisoft\\AVG Free\\avgw.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgw.exe:*:Enabled:AVG Free Edition for Windows"
"C:\\Program Files\\Microsoft ActiveSync\\WCESCOMM.EXE"="C:\\Program Files\\Microsoft ActiveSync\\WCESCOMM.EXE:*:Enabled:ActiveSync Connection Manager"
"C:\\Program Files\\Microsoft ActiveSync\\WCESMGR.EXE"="C:\\Program Files\\Microsoft ActiveSync\\WCESMGR.EXE:*:Enabled:ActiveSync Application"
"C:\\WINDOWS\\SYSTEM32\\USMT\\migwiz.exe"="C:\\WINDOWS\\SYSTEM32\\USMT\\migwiz.exe:*:Enabled:Files and Settings Transfer Wizard"
"C:\\Program Files\\Adobe\\Adobe Version Cue CS2\\bin\\VersionCueCS2.exe"="C:\\Program Files\\Adobe\\Adobe Version Cue CS2\\bin\\VersionCueCS2.exe:*:Enabled:Adobe Version Cue CS2"
"C:\\WINDOWS\\SYSTEM32\\SPOOL\\DRIVERS\\W32X86\\3\\SAGENT4.EXE"="C:\\WINDOWS\\SYSTEM32\\SPOOL\\DRIVERS\\W32X86\\3\\SAGENT4.EXE:*:Enabled:SAgent4"
"C:\\Documents and Settings\\H B Book Centre\\Desktop\\utorrent.exe"="C:\\Documents and Settings\\H B Book Centre\\Desktop\\utorrent.exe:*:Enabled:æTorrent"
"C:\\Documents and Settings\\H B Book Centre\\Desktop\\Ravi\\utorrent.exe"="C:\\Documents and Settings\\H B Book Centre\\Desktop\\Ravi\\utorrent.exe:*:Enabled:æTorrent"
"C:\\WINDOWS\\system32\\vssms32.exe"="C:\\WINDOWS\\system32\\vssms32.exe:*:Enabled:Dnode"
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"="C:\\Program Files\\Mozilla Firefox\\firefox.exe:*:Enabled:Firefox"
"C:\\Program Files\\Azureus\\Azureus.exe"="C:\\Program Files\\Azureus\\Azureus.exe:*:Enabled:Azureus"
"C:\\Program Files\\Windows Media Player\\wmplayer.exe"="C:\\Program Files\\Windows Media Player\\wmplayer.exe:*:Enabled:Windows Media Player"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"C:\\Program Files\\Google\\Google Talk\\googletalk.exe"="C:\\Program Files\\Google\\Google Talk\\googletalk.exe:*:Enabled:Google Talk"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\R-Studio Agent\\RSAgent.exe"="C:\\Program Files\\R-Studio Agent\\RSAgent.exe:*:Enabled:R-Studio Agent"
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"="C:\\Program Files\\Grisoft\\AVG7\\avginet.exe:*:Enabled:avginet.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe:*:Enabled:avgamsvr.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe:*:Enabled:avgcc.exe"
"C:\\Program Files\\PPLive\\PPLive.exe"="C:\\Program Files\\PPLive\\PPLive.exe:*:Enabled:PPLive"
"C:\\WINDOWS\\system32\\msnmsgr.exe"="C:\\WINDOWS\\system32\\msnmsgr.exe:*:Enabled:msnmsgr"
"C:\\Program Files\\Audible\\Bin\\AudibleDownloadHelper.exe"="C:\\Program Files\\Audible\\Bin\\AudibleDownloadHelper.exe:*:Enabled:Audible Download Manager"
"C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:æTorrent"
"C:\\Documents and Settings\\H B Book Centre\\My Documents\\Downloads\\utorrent.exe"="C:\\Documents and Settings\\H B Book Centre\\My Documents\\Downloads\\utorrent.exe:*:Enabled:æTorrent"
"C:\\Program Files\\Common Files\\Ahead\\Nero Web\\SetupX.exe"="C:\\Program Files\\Common Files\\Ahead\\Nero Web\\SetupX.exe:*:Enabled:Nero ProductSetup"
"C:\\Program Files\\FlashFXP\\FlashFXP.exe"="C:\\Program Files\\FlashFXP\\FlashFXP.exe:*:Enabled:FlashFXP v3"
"C:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\YahooMusicEngine.exe"="C:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\YahooMusicEngine.exe:*:Enabled:Yahoo! Music Jukebox"
"C:\\Program Files\\McAfee\\Managed VirusScan\\Agent\\myAgtSvc.exe"="C:\\Program Files\\McAfee\\Managed VirusScan\\Agent\\myAgtSvc.exe:*:Enabled:Managed Services Agent"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\WINDOWS\\SYSTEM32\\mpxa.exe"="C:\\WINDOWS\\SYSTEM32\\mpxa.exe:*:Enabled:mpxa"
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"="C:\\Program Files\\AVG\\AVG8\\avgemc.exe:*:Enabled:avgemc.exe"
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"="C:\\Program Files\\AVG\\AVG8\\avgupd.exe:*:Enabled:avgupd.exe"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\uusee\\UUSeePlayer.exe"="C:\\Program Files\\uusee\\UUSeePlayer.exe:*:Enabled:UUPlayer"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\FlashFXP\\FlashFXP.exe"="C:\\Program Files\\FlashFXP\\FlashFXP.exe:*:Enabled:FlashFXP v3"
"C:\\Program Files\\McAfee\\Managed VirusScan\\Agent\\myAgtSvc.exe"="C:\\Program Files\\McAfee\\Managed VirusScan\\Agent\\myAgtSvc.exe:*:Enabled:Managed Services Agent"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
Remaining Files :
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes :
Tue 4 Jan 2005 56 A.SHR — "C:\WINDOWS\SYSTEM32\EBDF1C0F5F.sys"
Wed 28 Dec 2005 1,024 A..HR — "C:\WINDOWS\SYSTEM32\NTICDMK32.dll"
Wed 28 Dec 2005 1,024 A..HR — "C:\WINDOWS\SYSTEM32\NTIMPEG2.dll"
Thu 21 Apr 2005 4,348 ..SH. — "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Thu 14 Apr 2005 50,176 A..H. — "C:\Documents and Settings\H B Book Centre\Application Data\RBShell500.dll"
Tue 9 Aug 2005 400 A.SH. — "C:\Documents and Settings\H B Book Centre\My Documents\drmv2key.bak"
Mon 29 Oct 2007 0 A.SH. — "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Mon 31 Mar 2008 256,512 …H. — "C:\Documents and Settings\H B Book Centre\Application Data\Microsoft\Word\~WRL3576.tmp"
Thu 7 Dec 2006 3,096,576 A..H. — "C:\Documents and Settings\H B Book Centre\Application Data\U3\temp\Launchpad Removal.exe"
Thu 2 Jun 2005 712,704 A.SH. — "C:\Documents and Settings\H B Book Centre\My Documents\My Pictures\Baker 2005\Haven '05\SIV7B0.tmp"
Wed 26 Feb 1997 21,504 A..H. — "C:\Program Files\Corel\Graphics10\Draw\Scripts\Misc\scpext.dll"
Mon 31 Oct 2005 8 A..H. — "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch5\lock.tmp"
Mon 16 Apr 2007 8 A..H. — "C:\Documents and Settings\Guest\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u1\lock.tmp"
Mon 16 Apr 2007 8 A..H. — "C:\Documents and Settings\Guest\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u2\lock.tmp"
Mon 16 Apr 2007 8 A..H. — "C:\Documents and Settings\Guest\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u3\lock.tmp"
Mon 16 Apr 2007 8 A..H. — "C:\Documents and Settings\Guest\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u4\lock.tmp"
Sat 24 Nov 2007 8 A..H. — "C:\Documents and Settings\Guest\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u5\lock.tmp"
Sun 15 Apr 2007 8 A..H. — "C:\Documents and Settings\H B Book Centre\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\lock.tmp"
Sun 15 Apr 2007 8 A..H. — "C:\Documents and Settings\H B Book Centre\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u2\lock.tmp"
Sun 15 Apr 2007 8 A..H. — "C:\Documents and Settings\H B Book Centre\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u3\lock.tmp"
Sun 15 Apr 2007 8 A..H. — "C:\Documents and Settings\H B Book Centre\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u4\lock.tmp"
Mon 16 Apr 2007 8 A..H. — "C:\Documents and Settings\H B Book Centre\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u5\lock.tmp"
Finished!
1. Ran ERUNT
2. Ran ATF Cleaner»
3. Ran SDFix (both in safe mode and on start-up)
4. Ran Malwarebytes' Anti-Malware
5. Last step instructs to post report results… if you have any further tips please let me know. Thanks in advance for the help with this.
Report.txt…
SDFix: Version 1.235
Run by [removed] on 13/10/2008 at 22:53
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Checking Services :
Name :
tdssserv
Path :
\systemroot\system32\drivers\TDSSserv.sys
tdssserv - Deleted
Restoring Default Security Values
Restoring Default Hosts File
Rebooting
Checking Files :
Trojan Files Found:
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat - Contains Links to Malware Sites! - Deleted
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat - Contains Links to Malware Sites! - Deleted
C:\WINDOWS\system32\ssqOEWMf.dll - Deleted
C:\~VMD8.TMP - Deleted
C:\~VMD9.TMP - Deleted
C:\~VMDA.TMP - Deleted
C:\~VMDB.TMP - Deleted
C:\~VMDC.TMP - Deleted
C:\~VMDD.TMP - Deleted
C:\~VMDE.TMP - Deleted
C:\~VMDF.TMP - Deleted
C:\~VME0.TMP - Deleted
C:\Documents and Settings\H B Book Centre\Application Data\Adobe\Player.exe - Deleted
C:\Documents and Settings\H B Book Centre\Application Data\Adobe\Player.exe.bak - Deleted
C:\Documents and Settings\H B Book Centre\Desktop\Malware Defender.url - Deleted
C:\Documents and Settings\H B Book Centre\Favorites\Malware Defender.url - Deleted
C:\Documents and Settings\H B Book Centre\Desktop\Protect Your Privacy.url - Deleted
C:\Documents and Settings\H B Book Centre\Favorites\Protect Your Privacy.url - Deleted
C:\Documents and Settings\H B Book Centre\Desktop\System Error Fixer.url - Deleted
C:\Documents and Settings\H B Book Centre\Favorites\System Error Fixer.url - Deleted
C:\WINDOWS\system32\wini104552664.exe - Deleted
C:\WINDOWS\hkr32.asm - Deleted
C:\WINDOWS\mainms.vpi - Deleted
C:\WINDOWS\megavid.cdt - Deleted
C:\WINDOWS\muotr.so - Deleted
C:\WINDOWS\system32\brastk.exe - Deleted
C:\WINDOWS\Temp\removalfile.bat - Deleted
Folder C:\Temp\1cb - Removed
Removing Temp Files
ADS Check :
Final Check :
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-13 23:06:47
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden services & system hive …
scanning hidden registry entries …
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\VE LXi Expert 6\\Program\\App.exe"="C:\\Program Files\\VE LXi Expert 6\\Program\\App.exe:*:Enabled:FlexiSIGN-PRO"
"C:\\Program Files\\VE LXi Expert 6\\Program\\App2.exe"="C:\\Program Files\\VE LXi Expert 6\\Program\\App2.exe:*:Enabled:Production"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"="C:\\Program Files\\Real\\RealPlayer\\realplay.exe:*:Enabled:RealPlayer"
"C:\\Program Files\\Grisoft\\AVG Free\\avgw.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgw.exe:*:Enabled:AVG Free Edition for Windows"
"C:\\Program Files\\Microsoft ActiveSync\\WCESCOMM.EXE"="C:\\Program Files\\Microsoft ActiveSync\\WCESCOMM.EXE:*:Enabled:ActiveSync Connection Manager"
"C:\\Program Files\\Microsoft ActiveSync\\WCESMGR.EXE"="C:\\Program Files\\Microsoft ActiveSync\\WCESMGR.EXE:*:Enabled:ActiveSync Application"
"C:\\WINDOWS\\SYSTEM32\\USMT\\migwiz.exe"="C:\\WINDOWS\\SYSTEM32\\USMT\\migwiz.exe:*:Enabled:Files and Settings Transfer Wizard"
"C:\\Program Files\\Adobe\\Adobe Version Cue CS2\\bin\\VersionCueCS2.exe"="C:\\Program Files\\Adobe\\Adobe Version Cue CS2\\bin\\VersionCueCS2.exe:*:Enabled:Adobe Version Cue CS2"
"C:\\WINDOWS\\SYSTEM32\\SPOOL\\DRIVERS\\W32X86\\3\\SAGENT4.EXE"="C:\\WINDOWS\\SYSTEM32\\SPOOL\\DRIVERS\\W32X86\\3\\SAGENT4.EXE:*:Enabled:SAgent4"
"C:\\Documents and Settings\\H B Book Centre\\Desktop\\utorrent.exe"="C:\\Documents and Settings\\H B Book Centre\\Desktop\\utorrent.exe:*:Enabled:æTorrent"
"C:\\Documents and Settings\\H B Book Centre\\Desktop\\Ravi\\utorrent.exe"="C:\\Documents and Settings\\H B Book Centre\\Desktop\\Ravi\\utorrent.exe:*:Enabled:æTorrent"
"C:\\WINDOWS\\system32\\vssms32.exe"="C:\\WINDOWS\\system32\\vssms32.exe:*:Enabled:Dnode"
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"="C:\\Program Files\\Mozilla Firefox\\firefox.exe:*:Enabled:Firefox"
"C:\\Program Files\\Azureus\\Azureus.exe"="C:\\Program Files\\Azureus\\Azureus.exe:*:Enabled:Azureus"
"C:\\Program Files\\Windows Media Player\\wmplayer.exe"="C:\\Program Files\\Windows Media Player\\wmplayer.exe:*:Enabled:Windows Media Player"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"C:\\Program Files\\Google\\Google Talk\\googletalk.exe"="C:\\Program Files\\Google\\Google Talk\\googletalk.exe:*:Enabled:Google Talk"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\R-Studio Agent\\RSAgent.exe"="C:\\Program Files\\R-Studio Agent\\RSAgent.exe:*:Enabled:R-Studio Agent"
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"="C:\\Program Files\\Grisoft\\AVG7\\avginet.exe:*:Enabled:avginet.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe:*:Enabled:avgamsvr.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe:*:Enabled:avgcc.exe"
"C:\\Program Files\\PPLive\\PPLive.exe"="C:\\Program Files\\PPLive\\PPLive.exe:*:Enabled:PPLive"
"C:\\WINDOWS\\system32\\msnmsgr.exe"="C:\\WINDOWS\\system32\\msnmsgr.exe:*:Enabled:msnmsgr"
"C:\\Program Files\\Audible\\Bin\\AudibleDownloadHelper.exe"="C:\\Program Files\\Audible\\Bin\\AudibleDownloadHelper.exe:*:Enabled:Audible Download Manager"
"C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:æTorrent"
"C:\\Documents and Settings\\H B Book Centre\\My Documents\\Downloads\\utorrent.exe"="C:\\Documents and Settings\\H B Book Centre\\My Documents\\Downloads\\utorrent.exe:*:Enabled:æTorrent"
"C:\\Program Files\\Common Files\\Ahead\\Nero Web\\SetupX.exe"="C:\\Program Files\\Common Files\\Ahead\\Nero Web\\SetupX.exe:*:Enabled:Nero ProductSetup"
"C:\\Program Files\\FlashFXP\\FlashFXP.exe"="C:\\Program Files\\FlashFXP\\FlashFXP.exe:*:Enabled:FlashFXP v3"
"C:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\YahooMusicEngine.exe"="C:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\YahooMusicEngine.exe:*:Enabled:Yahoo! Music Jukebox"
"C:\\Program Files\\McAfee\\Managed VirusScan\\Agent\\myAgtSvc.exe"="C:\\Program Files\\McAfee\\Managed VirusScan\\Agent\\myAgtSvc.exe:*:Enabled:Managed Services Agent"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\WINDOWS\\SYSTEM32\\mpxa.exe"="C:\\WINDOWS\\SYSTEM32\\mpxa.exe:*:Enabled:mpxa"
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"="C:\\Program Files\\AVG\\AVG8\\avgemc.exe:*:Enabled:avgemc.exe"
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"="C:\\Program Files\\AVG\\AVG8\\avgupd.exe:*:Enabled:avgupd.exe"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\uusee\\UUSeePlayer.exe"="C:\\Program Files\\uusee\\UUSeePlayer.exe:*:Enabled:UUPlayer"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\FlashFXP\\FlashFXP.exe"="C:\\Program Files\\FlashFXP\\FlashFXP.exe:*:Enabled:FlashFXP v3"
"C:\\Program Files\\McAfee\\Managed VirusScan\\Agent\\myAgtSvc.exe"="C:\\Program Files\\McAfee\\Managed VirusScan\\Agent\\myAgtSvc.exe:*:Enabled:Managed Services Agent"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
Remaining Files :
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes :
Tue 4 Jan 2005 56 A.SHR — "C:\WINDOWS\SYSTEM32\EBDF1C0F5F.sys"
Wed 28 Dec 2005 1,024 A..HR — "C:\WINDOWS\SYSTEM32\NTICDMK32.dll"
Wed 28 Dec 2005 1,024 A..HR — "C:\WINDOWS\SYSTEM32\NTIMPEG2.dll"
Thu 21 Apr 2005 4,348 ..SH. — "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Thu 14 Apr 2005 50,176 A..H. — "C:\Documents and Settings\H B Book Centre\Application Data\RBShell500.dll"
Tue 9 Aug 2005 400 A.SH. — "C:\Documents and Settings\H B Book Centre\My Documents\drmv2key.bak"
Mon 29 Oct 2007 0 A.SH. — "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Mon 31 Mar 2008 256,512 …H. — "C:\Documents and Settings\H B Book Centre\Application Data\Microsoft\Word\~WRL3576.tmp"
Thu 7 Dec 2006 3,096,576 A..H. — "C:\Documents and Settings\H B Book Centre\Application Data\U3\temp\Launchpad Removal.exe"
Thu 2 Jun 2005 712,704 A.SH. — "C:\Documents and Settings\H B Book Centre\My Documents\My Pictures\Baker 2005\Haven '05\SIV7B0.tmp"
Wed 26 Feb 1997 21,504 A..H. — "C:\Program Files\Corel\Graphics10\Draw\Scripts\Misc\scpext.dll"
Mon 31 Oct 2005 8 A..H. — "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch5\lock.tmp"
Mon 16 Apr 2007 8 A..H. — "C:\Documents and Settings\Guest\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u1\lock.tmp"
Mon 16 Apr 2007 8 A..H. — "C:\Documents and Settings\Guest\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u2\lock.tmp"
Mon 16 Apr 2007 8 A..H. — "C:\Documents and Settings\Guest\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u3\lock.tmp"
Mon 16 Apr 2007 8 A..H. — "C:\Documents and Settings\Guest\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u4\lock.tmp"
Sat 24 Nov 2007 8 A..H. — "C:\Documents and Settings\Guest\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u5\lock.tmp"
Sun 15 Apr 2007 8 A..H. — "C:\Documents and Settings\H B Book Centre\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\lock.tmp"
Sun 15 Apr 2007 8 A..H. — "C:\Documents and Settings\H B Book Centre\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u2\lock.tmp"
Sun 15 Apr 2007 8 A..H. — "C:\Documents and Settings\H B Book Centre\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u3\lock.tmp"
Sun 15 Apr 2007 8 A..H. — "C:\Documents and Settings\H B Book Centre\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u4\lock.tmp"
Mon 16 Apr 2007 8 A..H. — "C:\Documents and Settings\H B Book Centre\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u5\lock.tmp"
Finished!