Report from SDFix
SDFix: Version 1.112
Run by Thomas on 25/10/2007 at 02:02 PM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting...
Normal Mode:
Checking Files:
Trojan Files Found:
C:\CEP111.TMP - Deleted
C:\CEP14.TMP - Deleted
C:\CEP1B.TMP - Deleted
C:\CEP23.TMP - Deleted
C:\CEP72.TMP - Deleted
C:\CEPB.TMP - Deleted
C:\CEPBA.TMP - Deleted
C:\CEPD2.TMP - Deleted
C:\~GLHTTP1.TMP - Deleted
Removing Temp Files...
ADS Check:
C:\WINDOWS
No streams found.
C:\WINDOWS\system32
No streams found.
C:\WINDOWS\system32\svchost.exe
No streams found.
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.
Final Check:
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\Program Files\\Intuwave\\Shared\\mRouterRunTime\\mRouterRuntime.exe"="C:\\Program Files\\Intuwave\\Shared\\mRouterRunTime\\mRouterRuntime.exe:*:Enabled:mRouterRuntime"
"C:\\WINDOWS\\system32\\sessmgr.exe"="C:\\WINDOWS\\system32\\sessmgr.exe:*

isabled

xpsp2res.dll,-22019"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\WinMX\\WinMX.exe"="C:\\Program Files\\WinMX\\WinMX.exe:*:Enabled:WinMX Application"
"D:\\MOHAA\\moh_spearhead.exe"="D:\\MOHAA\\moh_spearhead.exe:*:Enabled:Medal of Honor Allied Assault(tm) Spearhead"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"="C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"D:\\MOHAA\\moh_Breakthrough.exe"="D:\\MOHAA\\moh_Breakthrough.exe:*:Enabled:Medal of Honor Allied Assault(tm) Breakthrough"
"C:\\Program Files\\BitTorrent\\btdownloadgui.exe"="C:\\Program Files\\BitTorrent\\btdownloadgui.exe:*:Enabled:btdownloadgui"
"D:\\WoW\\World of Warcraft\\WoW-1.9.4.5086-to-1.10.0.5195-enUS-downloader.exe"="D:\\WoW\\World of Warcraft\\WoW-1.9.4.5086-to-1.10.0.5195-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"D:\\WoW\\World of Warcraft\\BackgroundDownloader.exe"="D:\\WoW\\World of Warcraft\\BackgroundDownloader.exe:*:Enabled:Blizzard Downloader"
"D:\\WoW\\World of Warcraft\\WoW-1.10.2.5302-to-1.11.0.5428-enUS-downloader.exe"="D:\\WoW\\World of Warcraft\\WoW-1.10.2.5302-to-1.11.0.5428-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled

xpsp3res.dll,-20000"
"C:\\WINDOWS\\system32\\ftp.exe"="C:\\WINDOWS\\system32\\ftp.exe:*:Enabled:File Transfer Program"
"C:\\Program Files\\SpywareBot\\Quarantine\\06-01-2007-11-07-22\\10030.qit\\LimeWire.exe"="C:\\Program Files\\SpywareBot\\Quarantine\\06-01-2007-11-07-22\\10030.qit\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\BitTorrent\\bittorrent.exe"="C:\\Program Files\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"
"C:\\Program Files\\Warcraft III\\Warcraft III.exe"="C:\\Program Files\\Warcraft III\\Warcraft III.exe:*:Enabled:Warcraft III"
"C:\\Program Files\\Warcraft III\\Frozen Throne.exe"="C:\\Program Files\\Warcraft III\\Frozen Throne.exe:*:Enabled:Warcraft III - The Frozen Throne"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled

xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:æTorrent"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled

xpsp2res.dll,-22019"
"C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"="C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled

xpsp3res.dll,-20000"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
Remaining Files:
---------------
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes:
Wed 13 Oct 2004 1,694,208 ..SH. --- "C:\Program Files\Messenger\msmsgs.exe"
Wed 4 Aug 2004 60,416 A.SH. --- "C:\Program Files\Outlook Express\msimn.exe"
Sun 11 Jan 2004 18 A..H. --- "C:\WINDOWS\system32\ln32k.DLL"
Sat 20 Oct 2007 51,712 ..SHR --- "C:\WINDOWS\system32\wauservice.exe"
Thu 28 Apr 2005 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Mon 25 Oct 2004 20,992 A..H. --- "C:\Documents and Settings\Thomas\My Documents\~WRL0479.tmp"
Tue 3 Aug 2004 53,248 A.SHR --- "C:\WINDOWS\system32\drivers\1394bus.sys"
Tue 3 Aug 2004 187,776 A.SHR --- "C:\WINDOWS\system32\drivers\acpi.sys"
Thu 29 Aug 2002 11,648 A.SHR --- "C:\WINDOWS\system32\drivers\acpiec.sys"
Wed 4 Aug 2004 4,255 ..SHR --- "C:\WINDOWS\system32\drivers\adv01nt5.dll"
Wed 4 Aug 2004 3,967 ..SHR --- "C:\WINDOWS\system32\drivers\adv02nt5.dll"
Wed 4 Aug 2004 3,615 ..SHR --- "C:\WINDOWS\system32\drivers\adv05nt5.dll"
Wed 4 Aug 2004 3,647 ..SHR --- "C:\WINDOWS\system32\drivers\adv07nt5.dll"
Wed 4 Aug 2004 3,135 ..SHR --- "C:\WINDOWS\system32\drivers\adv08nt5.dll"
Wed 4 Aug 2004 3,711 ..SHR --- "C:\WINDOWS\system32\drivers\adv09nt5.dll"
Wed 4 Aug 2004 3,775 ..SHR --- "C:\WINDOWS\system32\drivers\adv11nt5.dll"
Tue 14 Feb 2006 142,464 A.SHR --- "C:\WINDOWS\system32\drivers\aec.sys"
Tue 3 Aug 2004 138,496 A.SHR --- "C:\WINDOWS\system32\drivers\afd.sys"
Tue 3 Aug 2004 42,368 ..SHR --- "C:\WINDOWS\system32\drivers\agp440.sys"
Tue 3 Aug 2004 44,928 ..SHR --- "C:\WINDOWS\system32\drivers\agpcpq.sys"
Tue 3 Aug 2004 42,752 ..SHR --- "C:\WINDOWS\system32\drivers\alim1541.sys"
Tue 3 Aug 2004 43,008 ..SHR --- "C:\WINDOWS\system32\drivers\amdagp.sys"
Tue 3 Aug 2004 36,992 A.SHR --- "C:\WINDOWS\system32\drivers\amdk6.sys"
Tue 3 Aug 2004 37,376 A.SHR --- "C:\WINDOWS\system32\drivers\amdk7.sys"
Tue 3 Aug 2004 60,800 A.SHR --- "C:\WINDOWS\system32\drivers\arp1394.sys"
Tue 3 Aug 2004 14,336 A.SHR --- "C:\WINDOWS\system32\drivers\asyncmac.sys"
Tue 3 Aug 2004 95,360 A.SHR --- "C:\WINDOWS\system32\drivers\atapi.sys"
Tue 3 Aug 2004 56,623 ..SHR --- "C:\WINDOWS\system32\drivers\ati1btxx.sys"
Tue 3 Aug 2004 11,615 ..SHR --- "C:\WINDOWS\system32\drivers\ati1mdxx.sys"
Tue 3 Aug 2004 12,047 ..SHR --- "C:\WINDOWS\system32\drivers\ati1pdxx.sys"
Tue 3 Aug 2004 30,671 ..SHR --- "C:\WINDOWS\system32\drivers\ati1raxx.sys"
Tue 3 Aug 2004 63,663 ..SHR --- "C:\WINDOWS\system32\drivers\ati1rvxx.sys"
Tue 3 Aug 2004 26,367 ..SHR --- "C:\WINDOWS\system32\drivers\ati1snxx.sys"
Tue 3 Aug 2004 21,343 ..SHR --- "C:\WINDOWS\system32\drivers\ati1ttxx.sys"
Tue 3 Aug 2004 36,463 ..SHR --- "C:\WINDOWS\system32\drivers\ati1tuxx.sys"
Tue 3 Aug 2004 29,455 ..SHR --- "C:\WINDOWS\system32\drivers\ati1xbxx.sys"
Tue 3 Aug 2004 34,735 ..SHR --- "C:\WINDOWS\system32\drivers\ati1xsxx.sys"
Tue 3 Aug 2004 327,040 ..SHR --- "C:\WINDOWS\system32\drivers\ati2mtaa.sys"
Tue 3 Aug 2004 701,440 ..SHR --- "C:\WINDOWS\system32\drivers\ati2mtag.sys"
Tue 3 Aug 2004 57,856 ..SHR --- "C:\WINDOWS\system32\drivers\atinbtxx.sys"
Tue 3 Aug 2004 13,824 ..SHR --- "C:\WINDOWS\system32\drivers\atinmdxx.sys"
Tue 3 Aug 2004 14,336 ..SHR --- "C:\WINDOWS\system32\drivers\atinpdxx.sys"
Tue 3 Aug 2004 52,224 ..SHR --- "C:\WINDOWS\system32\drivers\atinraxx.sys"
Tue 3 Aug 2004 104,960 ..SHR --- "C:\WINDOWS\system32\drivers\atinrvxx.sys"
Tue 3 Aug 2004 28,672 ..SHR --- "C:\WINDOWS\system32\drivers\atinsnxx.sys"
Tue 3 Aug 2004 13,824 ..SHR --- "C:\WINDOWS\system32\drivers\atinttxx.sys"
Tue 3 Aug 2004 73,216 ..SHR --- "C:\WINDOWS\system32\drivers\atintuxx.sys"
Tue 3 Aug 2004 31,744 ..SHR --- "C:\WINDOWS\system32\drivers\atinxbxx.sys"
Tue 3 Aug 2004 63,488 ..SHR --- "C:\WINDOWS\system32\drivers\atinxsxx.sys"
Tue 3 Aug 2004 59,904 A.SHR --- "C:\WINDOWS\system32\drivers\atmarpc.sys"
Thu 29 Aug 2002 31,360 A.SHR --- "C:\WINDOWS\system32\drivers\atmepvc.sys"
Tue 3 Aug 2004 55,936 A.SHR --- "C:\WINDOWS\system32\drivers\atmlane.sys"
Thu 29 Aug 2002 352,256 A.SHR --- "C:\WINDOWS\system32\drivers\atmuni.sys"
Wed 4 Aug 2004 21,183 ..SHR --- "C:\WINDOWS\system32\drivers\atv01nt5.dll"
Wed 4 Aug 2004 11,359 ..SHR --- "C:\WINDOWS\system32\drivers\atv02nt5.dll"
Wed 4 Aug 2004 25,471 ..SHR --- "C:\WINDOWS\system32\drivers\atv04nt5.dll"
Wed 4 Aug 2004 14,143 ..SHR --- "C:\WINDOWS\system32\drivers\atv06nt5.dll"
Wed 4 Aug 2004 17,279 ..SHR --- "C:\WINDOWS\system32\drivers\atv10nt5.dll"
Fri 17 Aug 2001 3,072 A.SHR --- "C:\WINDOWS\system32\drivers\audstub.sys"
Tue 3 Aug 2004 11,776 A.SHR --- "C:\WINDOWS\system32\drivers\bdasup.sys"
Thu 29 Aug 2002 4,224 A.SHR --- "C:\WINDOWS\system32\drivers\beep.sys"
Tue 3 Aug 2004 71,552 A.SHR --- "C:\WINDOWS\system32\drivers\bridge.sys"
Mon 24 Jul 2000 19,537 A.SHR --- "C:\WINDOWS\system32\drivers\BRPAR.SYS"
Wed 20 Feb 2002 6,430 A.SHR --- "C:\WINDOWS\system32\drivers\BT3CSer.sys"
Mon 14 Apr 2003 55,616 A.SHR --- "C:\WINDOWS\system32\drivers\Btcomm.sys"
Tue 3 Aug 2004 17,024 ..SHR --- "C:\WINDOWS\system32\drivers\bthenum.sys"
Tue 3 Aug 2004 38,016 ..SHR --- "C:\WINDOWS\system32\drivers\bthmodem.sys"