Here I am again,
Downloaded SDFix, extracted files and executed RunThis.bat…
Got this report:
===
SDFix: Version 1.109
Run by xxx xxx on 14/09/2007 at 18:42
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting…
Normal Mode:
Checking Files:
[b]Trojan Files Found:
C:\WINDOWS\alg.exe - Deleted[/b]
Removing Temp Files…
ADS Check:
C:\WINDOWS
No streams found.
C:\WINDOWS\system32
No streams found.
C:\WINDOWS\system32\svchost.exe
No streams found.
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.
Final Check:
Remaining Services:
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
“%windir%\system32\sessmgr.exe”=“%windir%\system32\sessmgr.exe::enabled:@xpsp2res.dll,-22019"
“C:\WINDOWS\system32\java.exe”="C:\WINDOWS\system32\java.exe::Enabled:Java™ 2 Platform Standard Edition binary”
“C:\Program Files\WS_FTP\WS_FTP95.exe”=“C:\Program Files\WS_FTP\WS_FTP95.exe::Enabled:WS_FTP 95"
“C:\Documents and Settings\xxx xxx\utorrent.exe”="C:\Documents and Settings\xxx xxx\utorrent.exe::Enabled:æTorrent”
“C:\Program Files\eMule\emule.exe”=“C:\Program Files\eMule\emule.exe::Enabled:eMule"
“C:\Program Files\JackSMS 3\JackSMS.exe”="C:\Program Files\JackSMS 3\JackSMS.exe::Enabled:JackSMS”
“C:\Program Files\Spyware Terminator\SpywareTerminator.Exe”=“C:\Program Files\Spyware Terminator\SpywareTerminator.Exe::Enabled:Spyware Terminator"
“C:\Program Files\Bonjour\mDNSResponder.exe”="C:\Program Files\Bonjour\mDNSResponder.exe::Disabled:Bonjour”
“C:\Documents and Settings\xxx xxx\Programs\utorrent.exe”=“C:\Documents and Settings\xxx xxx\Programs\utorrent.exe:*:Enabled:æTorrent”
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
“%windir%\system32\sessmgr.exe”=“%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019”
Remaining Files:
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes:
Thu 13 Sep 2007 2,402,304 A.SH. — “C:\WINDOWS\alerter.exe”
Thu 13 Sep 2007 888,320 A.SH. — “C:\WINDOWS\hg1.exe”
Sat 19 Nov 2005 4,348 A.SH. — “C:\Documents and Settings\All Users\DRM\DRMv1.bak”
Sun 23 Apr 2006 136,192 A…H. — “C:\Documents and Settings\xxx xxx\My Documents\eBook\Translations\xxx\xxx~WRL0691.TMP”
Wed 6 Jul 2005 281,600 A…H. — “C:\Documents and Settings\xxx xxx\My Documents\eBook\Translations\xxx\xxx~WRL0022.TMP”
Wed 6 Jul 2005 279,040 A…H. — “C:\Documents and Settings\xxx xxx\My Documents\eBook\Translations\xxx\xxx~WRL0301.TMP”
Wed 6 Jul 2005 280,576 A…H. — “C:\Documents and Settings\xxx xxx\My Documents\eBook\Translations\xxx\xxx~WRL0523.TMP”
Wed 6 Jul 2005 288,768 A…H. — “C:\Documents and Settings\xxx xxx\My Documents\eBook\Translations\xxx\xxx~WRL0542.TMP”
Wed 6 Jul 2005 281,088 A…H. — “C:\Documents and Settings\xxx xxx\My Documents\eBook\Translations\xxx\xxx~WRL1906.TMP”
Wed 6 Jul 2005 285,184 A…H. — “C:\Documents and Settings\xxx xxx\My Documents\eBook\Translations\xxx\xxx~WRL1930.TMP”
Wed 6 Jul 2005 281,088 A…H. — “C:\Documents and Settings\xxx xxx\My Documents\eBook\Translations\xxx\xxx~WRL1953.TMP”
Wed 6 Jul 2005 284,160 A…H. — “C:\Documents and Settings\xxx xxx\My Documents\eBook\Translations\xxx\xxx~WRL2415.TMP”
Wed 6 Jul 2005 285,696 A…H. — “C:\Documents and Settings\xxx xxx\My Documents\eBook\Translations\xxx\xxx~WRL3055.TMP”
Wed 6 Jul 2005 280,064 A…H. — “C:\Documents and Settings\xxx xxx\My Documents\eBook\Translations\xxx\xxx~WRL3132.TMP”
Wed 6 Jul 2005 281,088 A…H. — “C:\Documents and Settings\xxx xx\My Documents\eBook\Translations\xxx\xxx~WRL3250.TMP”
Wed 6 Jul 2005 280,576 A…H. — “C:\Documents and Settings\xxx xxx\My Documents\eBook\Translations\xxx\xxx~WRL3486.TMP”
Wed 6 Jul 2005 281,088 A…H. — “C:\Documents and Settings\xxx xxx\My Documents\eBook\Translations\xxx\xxx~WRL3600.TMP”
Wed 6 Jul 2005 281,088 A…H. — “C:\Documents and Settings\xxx xxx\My Documents\eBook\Translations\xxx\xxx~WRL3612.TMP”
Wed 6 Jul 2005 280,576 A…H. — “C:\Documents and Settings\xxx xxx\My Documents\eBook\Translations\xxx\xxx~WRL3669.TMP”
Wed 6 Jul 2005 285,184 A…H. — “C:\Documents and Settings\xxx xxx\My Documents\eBook\Translations\xxx\xxx~WRL3852.TMP”
Wed 6 Jul 2005 284,160 A…H. — “C:\Documents and Settings\xxx xxx\My Documents\eBook\Translations\xxx\xxx~WRL3853.TMP”
Wed 6 Jul 2005 280,064 A…H. — “C:\Documents and Settings\xxx xxx\My Documents\eBook\Translations\xxx\xxx~WRL3924.TMP”
Wed 6 Jul 2005 281,600 A…H. — “C:\Documents and Settings\xxx xxx\My Documents\eBook\Translations\xxx\xxx~WRL3963.TMP”
Wed 6 Jul 2005 286,720 A…H. — “C:\Documents and Settings\xxx xxx\My Documents\eBook\Translations\xxx\xxx~WRL4003.TMP”
Finished!
===
Done?
Thank you so much! 