PDA

View Full Version : Complete screw up



reckless
2008-02-08, 01:54
Ok, first off, im a noobie here so Hi everyone.
I came across this cause i've been rackin my pea brain and have really (hopefully not) fudged things up.

I have the ntos.exe virus/trojan. got it a couple days ago and tried to fix this on my own with different help topics i found on the net. things have gotten worse.

here's what ive done so far.

I got these programs and ran them all; process explorer, HJt, spybot, SDFix, trojan remover, startup list.

I have KAV 6.0 and a free version of AVG.

I havent 'fixed' anything when using HJt but i did use SDFix and after it went through its cycle I cant get into my windows account. all i see is my wallpaper (Deck16 woo lol)

I figure I should start by posting the logs for HJt and SDfix?




Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:51:24 PM, on 2/7/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://housecall.trendmicro.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: {35f385e6-5deb-7989-4cc4-b19a9c6e1229} - {9221e6c9-a91b-4cc4-9897-bed56e583f53} - C:\WINDOWS\system32\ykphonxk.dll
O2 - BHO: (no name) - {E180F496-8A4B-44E2-9FE0-0364E345DB7F} - (no file)
O2 - BHO: (no name) - {E2E46D88-2CE1-439D-A982-1B205A225EAB} - C:\WINDOWS\system32\geeby.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SB Live! 24-bit\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe"
O4 - HKLM\..\Run: [StrgSync.exe] C:\Program Files\StorageSync\StrgSync.exe -w
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SDFix] C:\SDFix\RunThis.bat /second
O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe
O4 - HKLM\..\RunOnce: [SDFix] C:\SDFix\RunThis.bat /second
O4 - HKLM\..\RunOnce: [Trojan Remover] "C:\Program Files\Trojan Remover\RMVTRJAN.EXE" /restart
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\ie_banner_deny.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\scieplugin.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} (YazzleActiveX Control) - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1123
O20 - Winlogon Notify: bpgefaef - C:\WINDOWS\
O20 - Winlogon Notify: mljjh - C:\WINDOWS\
O22 - SharedTaskScheduler: {93ac7c30-3878-4eaa-9420-7977285df5b1} - cinnamomum - (no file)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Kaspersky Internet Security 6.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe (file missing)

--
End of file - 6244 bytes




sdfix is next post cause its too long..

reckless
2008-02-08, 01:55
Here's hoping you dudes can help.. im out of options, actually my last option is to throw this pc off the highest building i can find!


and here's the SDFix log.....



SDFix: Version 1.138

Run by Administrator on Thu 02/07/2008 at 04:42 PM

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:


Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting...


Normal Mode:
Checking Files:

Trojan Files Found:

C:\WINDOWS\system32\tmp1AB.tmp - Deleted
C:\WINDOWS\Temp\$b17a2e8.tmp - Deleted
C:\WINDOWS\system32\ntos.exe - Deleted
C:\WINDOWS\system32\wsnpoem\audio.dll - Deleted
C:\WINDOWS\system32\wsnpoem\video.dll - Deleted



Folder C:\WINDOWS\system32\wsnpoem - Removed


Removing Temp Files...

ADS Check:



Final Check:

catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-07 17:02:13
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden services & system hive ...

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"p0"="C:\Program Files\Alcohol Soft\Alcohol 120\"
"h0"=dword:00000001
"ujdew"=hex:84,f9,a1,fd,54,2a,4b,8d,d4,e8,bb,48,15,ff,d4,97,af,19,7b,a0,05,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:00,9b,52,d5,ef,fc,ab,ac,01,30,c2,79,05,33,62,7e,18,89,78,6c,08,..
"p0"="C:\Program Files\DAEMON Tools\"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"khjeh"=hex:27,ef,b8,3f,25,10,6c,c7,7b,dc,d2,4d,96,85,fb,0d,4e,4e,e2,2e,23,..
"a0"=hex:20,01,00,00,fd,7e,8e,a5,1a,af,11,c6,c5,d8,40,70,ab,70,75,1a,03,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:92,48,0a,a9,b3,00,e6,c1,8f,63,a0,7a,c7,86,c8,30,3e,51,ed,05,bc,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41]
"khjeh"=hex:8a,3a,af,ae,f6,4d,6a,2a,f9,b5,5b,b6,49,24,b6,07,b0,a9,6e,9a,b3,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42]
"khjeh"=hex:35,2d,06,83,c5,15,2a,e2,49,95,1c,52,80,ac,67,e7,05,e9,71,fd,05,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"p0"="C:\Program Files\Alcohol Soft\Alcohol 120\"
"h0"=dword:00000001
"ujdew"=hex:84,f9,a1,fd,54,2a,4b,8d,d4,e8,bb,48,15,ff,d4,97,af,19,7b,a0,05,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:00,9b,52,d5,ef,fc,ab,ac,01,30,c2,79,05,33,62,7e,18,89,78,6c,08,..
"p0"="C:\Program Files\DAEMON Tools\"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"khjeh"=hex:27,ef,b8,3f,25,10,6c,c7,7b,dc,d2,4d,96,85,fb,0d,4e,4e,e2,2e,23,..
"a0"=hex:20,01,00,00,fd,7e,8e,a5,1a,af,11,c6,c5,d8,40,70,ab,70,75,1a,03,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:64,62,04,00,b8,db,4b,00,80,a4,63,00,a0,ff,ff,ff,6e,6b,20,00,40,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41]
"khjeh"=hex:00,7e,5a,b6,fb,00,37,a8,9b,4b,93,3b,01,0f,db,bb,1e,2a,83,cc,d8,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42]
"khjeh"=hex:c3,89,5c,fd,53,14,7c,30,c6,94,06,3c,2a,19,c2,b9,69,7a,37,85,37,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:dd457f85
"s2"=dword:455a00ae
"h0"=dword:00000002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"p0"="C:\Program Files\Alcohol Soft\Alcohol 120\"
"h0"=dword:00000001
"ujdew"=hex:84,f9,a1,fd,54,2a,4b,8d,d4,e8,bb,48,15,ff,d4,97,af,19,7b,a0,05,..

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:00,9b,52,d5,ef,fc,ab,ac,01,30,c2,79,05,33,62,7e,18,89,78,6c,08,..
"p0"="C:\Program Files\DAEMON Tools\"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"khjeh"=hex:27,ef,b8,3f,25,10,6c,c7,7b,dc,d2,4d,96,85,fb,0d,4e,4e,e2,2e,23,..
"a0"=hex:20,01,00,00,fd,7e,8e,a5,1a,af,11,c6,c5,d8,40,70,ab,70,75,1a,03,..

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:64,62,04,00,b0,7e,49,00,b8,9b,49,00,98,ff,ff,ff,25,00,53,00,79,..

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41]
"khjeh"=hex:00,7e,5a,b6,fb,00,37,a8,9b,4b,93,3b,01,0f,db,bb,1e,2a,83,cc,d8,..

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42]
"khjeh"=hex:c3,89,5c,fd,53,14,7c,30,c6,94,06,3c,2a,19,c2,b9,69,7a,37,85,37,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"p0"="C:\Program Files\Alcohol Soft\Alcohol 120\"
"h0"=dword:00000001
"ujdew"=hex:84,f9,a1,fd,54,2a,4b,8d,d4,e8,bb,48,15,ff,d4,97,af,19,7b,a0,05,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:00,9b,52,d5,ef,fc,ab,ac,01,30,c2,79,05,33,62,7e,18,89,78,6c,08,..
"p0"="C:\Program Files\DAEMON Tools\"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"khjeh"=hex:27,ef,b8,3f,25,10,6c,c7,7b,dc,d2,4d,96,85,fb,0d,4e,4e,e2,2e,23,..
"a0"=hex:20,01,00,00,fd,7e,8e,a5,1a,af,11,c6,c5,d8,40,70,ab,70,75,1a,03,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:64,62,04,00,a8,5d,a4,00,00,00,00,00,e8,ff,ff,ff,20,90,a4,00,20,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41]
"khjeh"=hex:00,7e,5a,b6,fb,00,37,a8,9b,4b,93,3b,01,0f,db,bb,1e,2a,83,cc,d8,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42]
"khjeh"=hex:c3,89,5c,fd,53,14,7c,30,c6,94,06,3c,2a,19,c2,b9,69,7a,37,85,37,..

scanning hidden registry entries ...

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\\24 L]
"Order"=hex:08,00,00,00,02,00,00,00,14,01,00,00,01,00,00,00,02,00,00,00,84,..
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\\32 f]
"Order"=hex:08,00,00,00,02,00,00,00,0c,00,00,00,01,00,00,00,00,00,00,00

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\\32 f\Illusion]
"Order"=hex:08,00,00,00,02,00,00,00,76,00,00,00,01,00,00,00,01,00,00,00,6a,..

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\\32 f\Illusion\RapeLay]
"Order"=hex:08,00,00,00,02,00,00,00,06,01,00,00,01,00,00,00,02,00,00,00,76,..

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\\32 f\Queen\x192{\x192\x201c\x192W\x192\x2021\x192\x2039\x201a\xcc\x81I\x81@\x81`\x8f\x2014\x2030\xa4\x201a\xcd\x90\xa7\x2022\x17e\x201a\xf0\x2019E\x201a\xa2\x201a\xbe\x81`]
"Order"=hex:08,00,00,00,02,00,00,00,12,02,00,00,01,00,00,00,03,00,00,00,c0,..

scanning hidden files ...


scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 6


Remaining Services:
------------------



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\BitTorrent\\bittorrent.exe"="C:\\Program Files\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"
"C:\\Program Files\\eDonkey2000\\edonkey2000.exe"="C:\\Program Files\\eDonkey2000\\edonkey2000.exe:*:Enabled:edonkey2000"
"C:\\Program Files\\IGN\\Download Manager\\DLM.exe"="C:\\Program Files\\IGN\\Download Manager\\DLM.exe:*:Enabled:Download Manager"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"C:\\Program Files\\Ubisoft\\Tom Clancy's Rainbow Six Vegas\\Binaries\\R6Vegas_Game.exe"="C:\\Program Files\\Ubisoft\\Tom Clancy's Rainbow Six Vegas\\Binaries\\R6Vegas_Game.exe:*:Enabled:Rainbow Six Vegas"
"C:\\Program Files\\Ubisoft\\Tom Clancy's Rainbow Six Vegas\\Binaries\\R6Vegas_Launcher.exe"="C:\\Program Files\\Ubisoft\\Tom Clancy's Rainbow Six Vegas\\Binaries\\R6Vegas_Launcher.exe:*:Enabled:Rainbow Six Vegas Updater"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\Program Files\\BitLord\\BitLord.exe"="C:\\Program Files\\BitLord\\BitLord.exe:*:Enabled:BitLord"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire PRO 4.10.0"
"C:\\SOF2_playable\\SoF2MP.exe"="C:\\SOF2_playable\\SoF2MP.exe:*:Enabled:SoF2MP"
"C:\\Program Files\\Microsoft Games\\Halo\\halo.exe"="C:\\Program Files\\Microsoft Games\\Halo\\halo.exe:*:Enabled:Halo"
"C:\\Program Files\\Microsoft Games\\Rise of Nations\\rise.exe"="C:\\Program Files\\Microsoft Games\\Rise of Nations\\rise.exe:*:Enabled:Rise of Nations"
"C:\\wormsarm\\WA.exe"="C:\\wormsarm\\WA.exe:*:Enabled:Worms Armageddon"
"C:\\SOF2_full\\SoF2MP.exe"="C:\\SOF2_full\\SoF2MP.exe:*:Enabled:SoF2MP"
"C:\\Program Files\\eMule\\emule.exe"="C:\\Program Files\\eMule\\emule.exe:*:Enabled:eMule"
"C:\\Program Files\\Xfire\\Xfire.exe"="C:\\Program Files\\Xfire\\Xfire.exe:*:Enabled:Xfire"
"C:\\WINDOWS\\system32\\PnkBstrA.exe"="C:\\WINDOWS\\system32\\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\\WINDOWS\\system32\\PnkBstrB.exe"="C:\\WINDOWS\\system32\\PnkBstrB.exe:*:Enabled:PnkBstrB"
"E:\\Unreal Tournament 3\\Binaries\\UT3.exe"="E:\\Unreal Tournament 3\\Binaries\\UT3.exe:*:Enabled:Unreal Tournament 3"
"E:\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"="E:\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe:*:Enabled:Call of Duty(R) 4 - Modern Warfare(TM) "
"C:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"="C:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe:*:Enabled:Battlefield 2"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

Remaining Files:
---------------

File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes:

Sun 30 Jul 2006 47,870,976 A..H. --- "C:\Extra\~WRL0003.tmp"
Mon 19 Sep 2005 19,456 A..H. --- "C:\512BackUp\army 2005\~WRL0003.tmp"
Mon 19 Sep 2005 20,480 A..H. --- "C:\512BackUp\army 2005\~WRL2064.tmp"
Mon 19 Sep 2005 19,968 A..H. --- "C:\512BackUp\army 2005\~WRL2335.tmp"
Mon 19 Sep 2005 20,480 A..H. --- "C:\512BackUp\army 2005\~WRL2596.tmp"
Sun 8 Apr 2007 46,592 A..H. --- "C:\512BackUp\communication\~WRL2379.tmp"
Mon 22 Jan 2007 24,576 A..H. --- "C:\512BackUp\grad school\~WRL0001.tmp"
Mon 22 Jan 2007 24,576 A..H. --- "C:\512BackUp\grad school\~WRL0003.tmp"
Thu 25 Jan 2007 26,112 A..H. --- "C:\512BackUp\grad school\~WRL0636.tmp"
Thu 25 Jan 2007 26,624 A..H. --- "C:\512BackUp\grad school\~WRL0934.tmp"
Thu 25 Jan 2007 26,112 A..H. --- "C:\512BackUp\grad school\~WRL0952.tmp"
Thu 25 Jan 2007 29,184 A..H. --- "C:\512BackUp\grad school\~WRL1704.tmp"
Thu 25 Jan 2007 26,112 A..H. --- "C:\512BackUp\grad school\~WRL1809.tmp"
Thu 25 Jan 2007 26,624 A..H. --- "C:\512BackUp\grad school\~WRL1975.tmp"
Mon 22 Jan 2007 27,136 A..H. --- "C:\512BackUp\grad school\~WRL2029.tmp"
Thu 25 Jan 2007 26,112 A..H. --- "C:\512BackUp\grad school\~WRL2082.tmp"
Sun 7 Jan 2007 63,488 A..H. --- "C:\512BackUp\grad school\~WRL2099.tmp"
Thu 25 Jan 2007 26,112 A..H. --- "C:\512BackUp\grad school\~WRL2147.tmp"
Thu 25 Jan 2007 29,184 A..H. --- "C:\512BackUp\grad school\~WRL2657.tmp"
Thu 25 Jan 2007 29,184 A..H. --- "C:\512BackUp\grad school\~WRL3006.tmp"
Thu 25 Jan 2007 26,112 A..H. --- "C:\512BackUp\grad school\~WRL3419.tmp"
Wed 13 Sep 2006 25,600 A..H. --- "C:\512BackUp\med apps\~WRL0018.tmp"
Wed 13 Sep 2006 25,088 A..H. --- "C:\512BackUp\med apps\~WRL0427.tmp"
Wed 13 Sep 2006 25,600 A..H. --- "C:\512BackUp\med apps\~WRL0888.tmp"
Wed 13 Sep 2006 22,528 A..H. --- "C:\512BackUp\med apps\~WRL1155.tmp"
Wed 13 Sep 2006 24,576 A..H. --- "C:\512BackUp\med apps\~WRL1191.tmp"
Mon 11 Sep 2006 21,504 A..H. --- "C:\512BackUp\med apps\~WRL1433.tmp"
Wed 13 Sep 2006 24,064 A..H. --- "C:\512BackUp\med apps\~WRL1556.tmp"
Mon 11 Sep 2006 24,064 A..H. --- "C:\512BackUp\med apps\~WRL1769.tmp"
Wed 13 Sep 2006 23,552 A..H. --- "C:\512BackUp\med apps\~WRL1919.tmp"
Wed 13 Sep 2006 23,040 A..H. --- "C:\512BackUp\med apps\~WRL1950.tmp"
Wed 13 Sep 2006 23,040 A..H. --- "C:\512BackUp\med apps\~WRL1955.tmp"
Wed 13 Sep 2006 25,088 A..H. --- "C:\512BackUp\med apps\~WRL2083.tmp"
Wed 13 Sep 2006 22,528 A..H. --- "C:\512BackUp\med apps\~WRL2514.tmp"
Wed 13 Sep 2006 22,528 A..H. --- "C:\512BackUp\med apps\~WRL3583.tmp"
Wed 13 Sep 2006 25,088 A..H. --- "C:\512BackUp\med apps\~WRL3756.tmp"
Tue 24 Oct 2006 25,600 A..H. --- "C:\512BackUp\Sites\~WRL1988.tmp"
Thu 7 Feb 2008 31,266 ..SH. --- "C:\WINDOWS\system32\bpgefaef.dllbox"
Fri 21 Jul 2006 749,116 A.SH. --- "C:\WINDOWS\system32\hjjlm.tmp"
Thu 20 Jul 2006 750,294 A.SH. --- "C:\WINDOWS\system32\hjjlm.bak2"
Mon 3 Jul 2006 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Fri 5 May 2006 179,712 A..H. --- "C:\Extra\TorScotR\marg\~WRL0042.tmp"
Fri 5 May 2006 200,192 A..H. --- "C:\Extra\TorScotR\marg\~WRL0518.tmp"
Fri 5 May 2006 323,584 A..H. --- "C:\Extra\TorScotR\marg\~WRL0539.tmp"
Fri 5 May 2006 306,176 A..H. --- "C:\Extra\TorScotR\marg\~WRL1842.tmp"
Fri 5 May 2006 199,680 A..H. --- "C:\Extra\TorScotR\marg\~WRL2289.tmp"
Fri 5 May 2006 185,344 A..H. --- "C:\Extra\TorScotR\marg\~WRL2317.tmp"
Fri 5 May 2006 200,192 A..H. --- "C:\Extra\TorScotR\marg\~WRL3478.tmp"
Fri 5 May 2006 308,736 A..H. --- "C:\Extra\TorScotR\marg\~WRL3502.tmp"
Thu 20 Jul 2006 0 A.SH. --- "C:\Program Files\Common Files\F?nts\OOLSV~1.EXE"
Mon 3 Jul 2006 887 A..H. --- "C:\Program Files\InterActual\InterActual Player\iti156.tmp"
Tue 5 Feb 2008 0 A..H. --- "C:\Documents and Settings\Dags\Local Settings\Temp\5d40f77hpf770.exe"
Sat 2 Feb 2008 5,853 ...HR --- "C:\Documents and Settings\Dags\Application Data\SecuROM\UserData\securom_v7_01.bak"
Mon 27 Aug 2007 99,840 A..H. --- "C:\Documents and Settings\Dags\My Documents\KTown\Tutor\~WRL0262.tmp"
Mon 27 Aug 2007 100,352 A..H. --- "C:\Documents and Settings\Dags\My Documents\KTown\Tutor\~WRL2560.tmp"
Mon 27 Aug 2007 100,864 A..H. --- "C:\Documents and Settings\Dags\My Documents\KTown\Tutor\~WRL2771.tmp"
Fri 17 Aug 2007 44,544 A..H. --- "C:\Documents and Settings\Dags\My Documents\KTown\F\Pashto\~WRL0001.tmp"
Mon 27 Aug 2007 99,840 A..H. --- "C:\Documents and Settings\Dags\My Documents\KTown\New Folder\Tutor\~WRL0262.tmp"
Mon 27 Aug 2007 100,352 A..H. --- "C:\Documents and Settings\Dags\My Documents\KTown\New Folder\Tutor\~WRL2560.tmp"
Mon 27 Aug 2007 100,864 A..H. --- "C:\Documents and Settings\Dags\My Documents\KTown\New Folder\Tutor\~WRL2771.tmp"

Finished!