I’m posting the contents of the Report.txt now, and will do the next bit and post again.
Report.txt
SDFix: Version 1.158
Run by Mr Cooper on 17/03/2008 at 14:53
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Checking Services :
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Restoring Default HomePage Value
Restoring Default Desktop Components Value
Rebooting
Checking Files :
Trojan Files Found:
C:\WINDOWS\Installer{57938394-a2c0-4aa7-a3be-8559401c32f2}\SetupMon.dll - Deleted
C:\Program Files\antiviirus.exe - Deleted
C:\WINDOWS\apdqnxp.dll - Deleted
C:\WINDOWS\fqspogw.exe - Deleted
Folder C:\WINDOWS\Installer{57938394-a2c0-4aa7-a3be-8559401c32f2} - Removed
Removing Temp Files
ADS Check :
[b]Final Check [/b]:
catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-17 15:01:35
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden services & system hive …
scanning hidden registry entries …
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 184
Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
“%windir%\system32\sessmgr.exe”=“%windir%\system32\sessmgr.exe::enabled:@xpsp2res.dll,-22019"
“C:\Program Files\Messenger\msmsgs.exe”="C:\Program Files\Messenger\msmsgs.exe::Enabled:Windows Messenger”
“%windir%\Network Diagnostic\xpnetdiag.exe”=“%windir%\Network Diagnostic\xpnetdiag.exe::Enabled:@xpsp3res.dll,-20000"
“C:\Program Files\MSN Messenger\msnmsgr.exe”="C:\Program Files\MSN Messenger\msnmsgr.exe::Enabled:Windows Live Messenger 8.1”
“C:\Program Files\MSN Messenger\livecall.exe”=“C:\Program Files\MSN Messenger\livecall.exe::Enabled:Windows Live Messenger 8.1 (Phone)"
“C:\Program Files\Real\RealPlayer\realplay.exe”="C:\Program Files\Real\RealPlayer\realplay.exe::Enabled:RealPlayer”
“C:\Program Files\Internet Explorer\iexplore.exe”=“C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer”
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
“%windir%\system32\sessmgr.exe”=“%windir%\system32\sessmgr.exe::enabled:@xpsp2res.dll,-22019"
“C:\Program Files\MSN Messenger\msncall.exe”="C:\Program Files\MSN Messenger\msncall.exe::Enabled:Windows Live Messenger 8.0 (Phone)”
“%windir%\Network Diagnostic\xpnetdiag.exe”=“%windir%\Network Diagnostic\xpnetdiag.exe::Enabled:@xpsp3res.dll,-20000"
“C:\Program Files\MSN Messenger\msnmsgr.exe”="C:\Program Files\MSN Messenger\msnmsgr.exe::Enabled:Windows Live Messenger 8.1”
“C:\Program Files\MSN Messenger\livecall.exe”=“C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)”
Remaining Files :
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes :
Thu 28 Oct 2004 1,142,784 A…H. — “C:\My Games\Incadia\Incadia.exe”
Tue 21 Sep 2004 4,348 A.SH. — “C:\Documents and Settings\All Users\DRM\DRMv1.bak”
Mon 24 Apr 2006 401 A.SH. — “C:\Documents and Settings\All Users\DRM\DRMv10.bak”
Wed 5 Mar 2008 22,786 …SHR — “C:\WINDOWS\Installer{d9bfcedd-23ba-472e-875c-b21807b7641c}\zip.dll”
Fri 8 Dec 2006 0 A.SH. — “C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp”
Fri 27 Jul 2007 19,456 …H. — “C:\Documents and Settings\Mr Cooper\My Documents\Mum’s bd picz~WRL3077.tmp”
Wed 19 Sep 2007 0 A…H. — “C:\WINDOWS\SoftwareDistribution\Download\393bb6d5cf2f8ddce679d2cc37627398\BIT2.tmp”
Tue 11 Jan 2005 174,592 …H. — “C:\Documents and Settings\Mr Cooper\Application Data\Microsoft\Templates~WRL0003.tmp”
Mon 18 Sep 2006 162,816 …H. — “C:\Documents and Settings\Mr Cooper\Application Data\Microsoft\Templates~WRL0005.tmp”
Fri 28 Apr 2006 49,152 …H. — “C:\Documents and Settings\Mr Cooper\Application Data\Microsoft\Templates~WRL0589.tmp”
Wed 10 Nov 2004 104,960 …H. — “C:\Documents and Settings\Mr Cooper\Application Data\Microsoft\Templates~WRL2001.tmp”
Wed 31 May 2006 78,336 …H. — “C:\Documents and Settings\Mr Cooper\Application Data\Microsoft\Word~WRL0004.tmp”
Thu 19 Oct 2006 175,104 …H. — “C:\Documents and Settings\Mr Cooper\Application Data\Microsoft\Word~WRL0063.tmp”
Mon 14 Feb 2005 20,992 …H. — “C:\Documents and Settings\Mr Cooper\Application Data\Microsoft\Word~WRL0584.tmp”
Fri 27 Jul 2007 4,721,152 …H. — “C:\Documents and Settings\Mr Cooper\Application Data\Microsoft\Word~WRL0927.tmp”
Sat 30 Jun 2007 174,080 …H. — “C:\Documents and Settings\Mr Cooper\Application Data\Microsoft\Word~WRL1863.tmp”
Fri 25 Jan 2008 2,074,112 …H. — “C:\Documents and Settings\Mr Cooper\Application Data\Microsoft\Word~WRL2387.tmp”
Wed 6 Jun 2007 271,360 …H. — “C:\Documents and Settings\Mr Cooper\Application Data\Microsoft\Word~WRL2393.tmp”
Wed 6 Jun 2007 246,784 …H. — “C:\Documents and Settings\Mr Cooper\Application Data\Microsoft\Word~WRL2583.tmp”
Mon 14 Feb 2005 19,456 …H. — “C:\Documents and Settings\Mr Cooper\Application Data\Microsoft\Word~WRL2813.tmp”
Sat 30 Jun 2007 199,680 …H. — “C:\Documents and Settings\Mr Cooper\Application Data\Microsoft\Word~WRL3445.tmp”
Sun 20 Jan 2008 283,648 …H. — “C:\Documents and Settings\Mr Cooper\Application Data\Microsoft\Word~WRL3577.tmp”
Wed 6 Jun 2007 273,920 …H. — “C:\Documents and Settings\Mr Cooper\Application Data\Microsoft\Word~WRL3825.tmp”
Finished!