Ok... here is my SDFix log;
---------------------------
SDFix: Version 1.230
Run by BBY MONITORS on Wed 10/01/2008 at 10:48 AM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Checking Services :
Restoring Default Security Values
Restoring Default Hosts File
Rebooting
Checking Files :
Trojan Files Found:
C:\WINDOWS\system32\TFTP1364 - Deleted
C:\WINDOWS\system32\TFTP148 - Deleted
C:\WINDOWS\system32\TFTP1632 - Deleted
C:\WINDOWS\system32\TFTP1900 - Deleted
C:\DOCUME~1\BBYMON~1\LOCALS~1\Temp\removalfile.bat - Deleted
Folder C:\Temp\1cb - Removed
Removing Temp Files
ADS Check :
Final Check :
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-01 11:02:18
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\sharedaccess\parameters\firewallpolicy\standard profile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\syste m32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\DigiPortal Software\\ChoiceMail\\ChoiceMail.exe"="C:\\Program Files\\DigiPortal Software\\ChoiceMail\\ChoiceMail.exe:*:Enabled:Cho iceMail"
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"="C:\\Program Files\\Grisoft\\AVG7\\avginet.exe:*:Enabled:avgine t.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe:*:Enabled:avgam svr.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe:*:Enabled:avgcc.ex e"
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe:*:Enabled:avgemc. exe"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\Intuit\\QuickBooks 2008\\QBDBMgrN.exe"="C:\\Program Files\\Intuit\\QuickBooks 2008\\QBDBMgrN.exe:*:Enabled:QuickBooks 2008 Data Manager"
"C:\\Documents and Settings\\BBY MONITORS\\Application Data\\SopCast\\adv\\SopAdver.exe"="C:\\Documents and Settings\\BBY MONITORS\\Application Data\\SopCast\\adv\\SopAdver.exe:*:Enabled:SopAdve r"
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\ \Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Ena bled:Yahoo! Messenger"
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Progra m Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Ya hoo! FT Server"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\sharedaccess\parameters\firewallpolicy\domainpr ofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\syste m32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
Remaining Files :
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes :
Sun 13 Apr 2008 1,695,232 ..SH. --- "C:\Program Files\Messenger\msmsgs.exe"
Mon 26 Apr 2004 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Tue 20 Jul 2004 400 ..SH. --- "C:\Documents and Settings\All Users\DRM\v2ks.bla.bak"
Tue 20 Jul 2004 48 ..SH. --- "C:\Documents and Settings\All Users\DRM\v2ks.sec.bak"
Tue 20 Jul 2004 400 ..SH. --- "C:\Documents and Settings\All Users\DRM\v3ks.bla.bak"
Tue 13 May 2008 12,159 ...H. --- "C:\Documents and Settings\BBY MONITORS\My Documents\~WRL0001.tmp"
Mon 7 Jul 2008 25,001 ...H. --- "C:\Documents and Settings\BBY MONITORS\My Documents\~WRL0002.tmp"
Sun 6 Jul 2008 26,418 ...H. --- "C:\Documents and Settings\BBY MONITORS\My Documents\~WRL0003.tmp"
Sat 5 Jul 2008 27,303 ...H. --- "C:\Documents and Settings\BBY MONITORS\My Documents\~WRL0005.tmp"
Tue 8 Jul 2008 25,183 ...H. --- "C:\Documents and Settings\BBY MONITORS\My Documents\~WRL0006.tmp"
Mon 7 Jul 2008 26,313 ...H. --- "C:\Documents and Settings\BBY MONITORS\My Documents\~WRL0024.tmp"
Fri 4 Jul 2008 24,303 ...H. --- "C:\Documents and Settings\BBY MONITORS\My Documents\~WRL0481.tmp"
Sun 6 Jul 2008 26,855 ...H. --- "C:\Documents and Settings\BBY MONITORS\My Documents\~WRL1488.tmp"
Mon 7 Jul 2008 11,653 ...H. --- "C:\Documents and Settings\BBY MONITORS\My Documents\~WRL1909.tmp"
Tue 8 Jul 2008 15,818 ...H. --- "C:\Documents and Settings\BBY MONITORS\My Documents\~WRL1960.tmp"
Mon 30 Jun 2008 14,985 ...H. --- "C:\Documents and Settings\BBY MONITORS\My Documents\~WRL1971.tmp"
Mon 7 Jul 2008 13,513 ...H. --- "C:\Documents and Settings\BBY MONITORS\My Documents\~WRL2238.tmp"
Wed 9 Jul 2008 11,755 ...H. --- "C:\Documents and Settings\BBY MONITORS\My Documents\~WRL2752.tmp"
Tue 8 Jul 2008 17,568 ...H. --- "C:\Documents and Settings\BBY MONITORS\My Documents\~WRL3646.tmp"
Mon 4 Oct 2004 417,792 A..H. --- "C:\Program Files\Canon\Canon Setup Utility 2.0\Maint.exe"
Tue 11 May 2004 61,440 A..H. --- "C:\Program Files\Canon\Canon Setup Utility 2.0\uinstrsc.dll"
Fri 8 Dec 2006 345 A..H. --- "C:\Program Files\InterActual\InterActual Player\itiA2.tmp"
Sat 11 Nov 2006 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Sat 17 May 2008 14,654 A..H. --- "C:\Documents and Settings\BBY MONITORS\My Documents\Dirty Work\~WRL0728.tmp"
Wed 9 Jul 2008 78,336 ...H. --- "C:\Documents and Settings\BBY MONITORS\Application Data\Microsoft\Word\~WRL0003.tmp"
Tue 8 Jul 2008 52,736 ...H. --- "C:\Documents and Settings\BBY MONITORS\Application Data\Microsoft\Word\~WRL3739.tmp"
Thu 29 May 2008 75,776 ...H. --- "C:\Documents and Settings\BBY MONITORS\Application Data\Microsoft\Word\~WRL3858.tmp"
Mon 16 Jun 2008 14,048 A..H. --- "C:\Documents and Settings\BBY MONITORS\My Documents\PPC Ad Construction\Blend Them In Like Laser Surgery - I Had It\~WRL0001.tmp"
Fri 18 Apr 2008 15,716 A..H. --- "C:\Documents and Settings\BBY MONITORS\My Documents\PPC Ad Construction\Phase 1 - Selling An InfoProduct with a Solution\~WRL0001.tmp"
Tue 29 Apr 2008 14,115 A..H. --- "C:\Documents and Settings\BBY MONITORS\My Documents\PPC Ad Construction\Phase 1 - Selling An InfoProduct with a Solution\~WRL0003.tmp"
Tue 29 Apr 2008 32,133 A..H. --- "C:\Documents and Settings\BBY MONITORS\My Documents\PPC Ad Construction\Phase 1 - Selling An InfoProduct with a Solution\~WRL2829.tmp"
Thu 8 May 2008 12,939 A..H. --- "C:\Documents and Settings\BBY MONITORS\My Documents\PPC Ad Construction\Phase 1 - Selling An InfoProduct with a Solution\Home Remedy Only\~WRL3564.tmp"
Finished!








