[b]SDFix: Version 1.236
/b
Run by Default on 2008-10-21 at 13:00
Microsoft Windows XP [version 5.1.2600]
Running From: C:\SDFix
[b]Checking Services
/b:
Restoring Default Security Values
Restoring Default Hosts File
Rebooting
[b]Checking Files
/b:
Trojan Files Found:
C:\Program Files\XP_Antispyware\htmlayout.dll - Deleted
C:\Program Files\XP_Antispyware\pthreadVC2.dll - Deleted
C:\Program Files\XP_Antispyware\XP_Antispyware.cfg - Deleted
C:\Program Files\XP_Antispyware\data\daily.cvd - Deleted
C:\Program Files\XP_Antispyware\Microsoft.VC80.CRT\Microsoft.VC80.CRT.manifest - Deleted
C:\Program Files\XP_Antispyware\Microsoft.VC80.CRT\msvcm80.dll - Deleted
C:\Program Files\XP_Antispyware\Microsoft.VC80.CRT\msvcp80.dll - Deleted
C:\Program Files\XP_Antispyware\Microsoft.VC80.CRT\msvcr80.dll - Deleted
C:\Documents and Settings\All Users\Documents\enym.ban - Deleted
C:\Documents and Settings\All Users\Documents\noryquferi.dat - Deleted
C:\Documents and Settings\All Users\Documents\oholi.dat - Deleted
C:\Documents and Settings\All Users\Documents\dacawo._sy - Deleted
C:\Program Files\Fichiers communs\vicufem._sy - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\Binaries3.cab4 - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\Binaries3.cab5 - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP1.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP10.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP11.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP12.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP13.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP14.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP15.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP16.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP17.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP18.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP19.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP1A.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP1B.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP1C.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP1D.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP1E.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP1F.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP2.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP20.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP21.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP22.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP23.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP24.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP25.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP26.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP27.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP28.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP29.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP2A.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP2B.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP2C.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP2D.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP2E.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP2F.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP3.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP30.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP31.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP32.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP33.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP34.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP35.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP36.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP37.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP38.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP39.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP3A.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP3B.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP3C.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP3D.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP3E.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP3F.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP4.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP40.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP41.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP42.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP43.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP44.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP45.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP46.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP47.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP48.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP49.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP4A.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP4B.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP4C.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP4D.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP4E.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP4F.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP5.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP50.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP51.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP52.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP53.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP54.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP55.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP56.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP57.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP58.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP59.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP5A.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP5B.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP5C.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP5D.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP5E.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP5F.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP6.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP60.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP61.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP62.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP63.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP64.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP65.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP66.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP67.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP68.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP69.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP6A.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP6B.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP6C.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP6D.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP6E.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP6F.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP7.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP70.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP71.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP72.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP73.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP74.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP75.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP76.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP77.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP78.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP79.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP7A.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP7B.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP7C.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP7D.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP7E.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP7F.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP8.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP80.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP81.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP82.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP83.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP84.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP85.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP86.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP87.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP88.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP89.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP8A.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP8B.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP8C.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP8D.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP8E.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP8F.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP9.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP90.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP91.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP92.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP93.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP94.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP95.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP96.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP97.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP98.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP99.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP9A.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP9B.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP9C.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP9D.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP9E.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMP9F.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPA.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPA0.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPA1.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPA2.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPA3.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPA4.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPA5.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPA6.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPA7.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPA8.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPA9.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPAA.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPAB.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPAC.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPAD.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPAE.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPAF.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPB.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPB0.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPB1.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPB2.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPB3.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPB4.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPB5.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPB6.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPB7.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPB8.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPB9.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPBA.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPBB.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPBC.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPBD.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPBE.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPBF.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPC.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPC0.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPC1.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPC2.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPC3.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPC4.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPC5.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPC6.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPC7.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPC8.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPC9.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPCA.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPCB.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPCC.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPCD.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPCE.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPCF.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPD.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPD0.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPD1.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPD2.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPD3.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPD4.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPD5.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPD6.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPD7.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPD8.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPD9.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPDA.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPDB.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPDC.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPDD.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPDE.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPDF.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPE.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPE0.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPE1.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPE2.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPE3.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPE4.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPE5.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPE6.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPE7.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPE8.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPE9.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPEA.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPEB.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPEC.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPED.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPEE.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPEF.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPF.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPF0.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPF1.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPF2.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPF3.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPF4.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPF5.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPF6.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPF7.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPF8.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPF9.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPFA.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPFB.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPFC.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPFD.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPFE.tmp - Deleted
C:\DOCUME~1\Default\LOCALS~1\Temp\TMPFF.tmp - Deleted
C:\Documents and Settings\Default\Application Data\Microsoft\Internet Explorer\Quick Launch\XP_AntiSpyware.lnk - Deleted
C:\WINDOWS\brastk.exe - Deleted
C:\WINDOWS\system32\brastk.exe - Deleted
C:\WINDOWS\system32\delself.bat - Deleted
Folder C:\Program Files\XP_Antispyware - Removed
Removing Temp Files
[b]ADS Check
/b:
[b]Final Check
/b:
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-10-21 13:07:37
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
[b]Remaining Services
/b:
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"C:\\Program Files\\NetMeeting\\conf.exe"="C:\\Program Files\\NetMeeting\\conf.exe:*:Enabled:Windows© NetMeeting©"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\StubInstaller.exe"="C:\\StubInstaller.exe:*:Enabled:LimeWire swarmed installer"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
[b]Remaining Files
/b:
File Backups: - C:\SDFix\backups\backups.zip
[b]Files with Hidden Attributes
/b:
Tue 3 Jul 2007 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
[b]Finished!
/b