Iminfected
New member
SDFix: Version 1.115
Run by Frogman on Thu 11/22/2007 at 11:52 PM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting...
Normal Mode:
Checking Files:
Trojan Files Found:
C:\WINDOWS\Fonts\Crack.exe - Deleted
C:\WINDOWS\Fonts\*.zip - 1 File(s) 637,944 bytes - Deleted
C:\WINDOWS\Fonts\'\*.zip - 982 File(s) 626,461,990 bytes - Deleted
Folder C:\WINDOWS\Fonts\' - Removed
Removing Temp Files...
ADS Check:
C:\WINDOWS
No streams found.
C:\WINDOWS\system32
No streams found.
C:\WINDOWS\system32\svchost.exe
No streams found.
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.
Final Check:
catchme 0.3.1262.1 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-22 23:56:27
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_UACFLT]
"NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_UACFLT\0000]
"Service"="uacFlt"
"Legacy"=dword:00000001
"ConfigFlags"=dword:00000000
"Class"="LegacyDriver"
"ClassGUID"="{8ECC055D-047F-11D1-A537-0000F8753ED1}"
"DeviceDesc"="Plantronics USB Audio Adapter EQ Filter Driver"
"Capabilities"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Control\Session Manager\Memory Management\PrefetchParameters]
"VideoInitTime"=dword:000010d8
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Control\Watchdog\Display]
"ShutdownCount"=dword:00000566
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\SharedAccess\Epoch]
"Epoch"=dword:00003283
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\SPBBCDrv\Parameters]
"Configuration"="C:\Program Files\Common Files\Symantec Shared\SPBBC\2007-11-21-2c9f.kc"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\Tcpip\Parameters\Interfaces\{00CD4987-2CB7-4631-9C5A-182743264320}]
"LeaseObtainedTime"=dword:47449851
"T1"=dword:47454111
"T2"=dword:4745bfa1
"LeaseTerminatesTime"=dword:4745e9d1
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\wscsvc]
"Start"=dword:00000004
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\{00CD4987-2CB7-4631-9C5A-182743264320}\Parameters\Tcpip]
"LeaseObtainedTime"=dword:47449851
"T1"=dword:47454111
"T2"=dword:4745bfa1
"LeaseTerminatesTime"=dword:4745e9d1
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\Program Files\\World of Warcraft\\WoW-1.7.1.4695-to-1.8.0-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-1.7.1.4695-to-1.8.0-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\WoW-1.8.3.4807-to-1.8.4.4878-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-1.8.3.4807-to-1.8.4.4878-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Documents and Settings\\Frogman\\My Documents\\Downloads\\Arathi_Basin_new_EG-downloader.exe"="C:\\Documents and Settings\\Frogman\\My Documents\\Downloads\\Arathi_Basin_new_EG-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\WoW-1.8.4.4878-to-1.9.0.4937-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-1.8.4.4878-to-1.9.0.4937-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\WoW-1.9.2.4996-to-1.9.3.5059-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-1.9.2.4996-to-1.9.3.5059-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\WoW-1.9.4.5086-to-1.10.0.5195-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-1.9.4.5086-to-1.10.0.5195-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\WINDOWS\\system32\\sessmgr.exe"="C:\\WINDOWS\\system32\\sessmgr.exe:*
isabled
xpsp2res.dll,-22019"
"C:\\Documents and Settings\\Frogman\\My Documents\\Downloads\\wow-ptr-downloader2.exe"="C:\\Documents and Settings\\Frogman\\My Documents\\Downloads\\wow-ptr-downloader2.exe:*:Enabled:Blizzard Downloader"
"C:\\Documents and Settings\\Frogman\\My Documents\\Downloads\\WoW-1.10.2.5302-to-0.11.0.5344-enUS-downloader.exe"="C:\\Documents and Settings\\Frogman\\My Documents\\Downloads\\WoW-1.10.2.5302-to-0.11.0.5344-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"="C:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\WoWTest\\WoW-0.11.0.5383-to-0.11.0.5413-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoWTest\\WoW-0.11.0.5383-to-0.11.0.5413-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\WoW-1.10.2.5302-to-1.11.0.5428-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-1.10.2.5302-to-1.11.0.5428-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\WoW-1.11.1.5462-to-1.11.2.5464-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-1.11.1.5462-to-1.11.2.5464-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Documents and Settings\\Frogman\\My Documents\\Downloads\\WoW-1.11.2.5464-to-0.12.0.5496-enUS-downloader.exe"="C:\\Documents and Settings\\Frogman\\My Documents\\Downloads\\WoW-1.11.2.5464-to-0.12.0.5496-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\WoWTest\\WoW-0.12.0.5537-to-0.12.0.5561-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoWTest\\WoW-0.12.0.5537-to-0.12.0.5561-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\StubInstaller.exe"="C:\\StubInstaller.exe:*:Enabled:LimeWire swarmed installer"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\World of Warcraft\\WoW-1.11.2.5464-to-1.12.0.5595-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-1.11.2.5464-to-1.12.0.5595-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Documents and Settings\\Frogman\\My Documents\\Downloads\\WoW-1.12.0.5595-to-0.12.1.5803-enUS-downloader.exe"="C:\\Documents and Settings\\Frogman\\My Documents\\Downloads\\WoW-1.12.0.5595-to-0.12.1.5803-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\WoW-1.12.0.5595-to-1.12.1.5875-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-1.12.0.5595-to-1.12.1.5875-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\Common Files\\AOL\\1152161668\\ee\\aim6.exe"="C:\\Program Files\\Common Files\\AOL\\1152161668\\ee\\aim6.exe:*
isabled:AIM"
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*
isabled:AOL Loader"
"C:\\Program Files\\Common Files\\AOL\\1152161668\\ee\\aolsoftware.exe"="C:\\Program Files\\Common Files\\AOL\\1152161668\\ee\\aolsoftware.exe:*
isabled:AOL Services"
"C:\\WINDOWS\\system32\\mmmdajfk.exe"="C:\\WINDOWS\\system32\\mmm"
"C:\\WINDOWS\\system32\\xnfrwhpt.exe"="C:\\WINDOWS\\system32\\xnf"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled
xpsp2res.dll,-22019"
Remaining Files:
---------------
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes:
Wed 4 Aug 2004 93,184 A.SH. --- "C:\Program Files\Internet Explorer\iexplore.exe"
Wed 13 Oct 2004 1,694,208 ..SH. --- "C:\Program Files\Messenger\msmsgs.exe"
Wed 4 Aug 2004 60,416 A.SH. --- "C:\Program Files\Outlook Express\msimn.exe"
Mon 1 Jan 2007 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Thu 25 Jan 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Fri 9 Sep 2005 1,740 A..HR --- "C:\Program Files\Common Files\Symantec Shared\Registry Backup\ccReg.reg"
Fri 9 Sep 2005 274,904 A..HR --- "C:\Program Files\Common Files\Symantec Shared\Registry Backup\CommonClient.reg"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico11.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico12.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico13.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico14.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico15.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico16.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico17.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico18.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico19.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico1A.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico1C.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico1D.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico1E.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico1F.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico20.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico23.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico24.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico25.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico26.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico27.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico28.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico29.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico2A.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico2B.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico2C.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico2D.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico2E.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico2F.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico30.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico31.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico32.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico33.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico34.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico35.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico36.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico37.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico38.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico39.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico3A.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico3B.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico3C.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico3D.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico3E.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico3F.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico40.tmp"
Finished!
Run by Frogman on Thu 11/22/2007 at 11:52 PM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting...
Normal Mode:
Checking Files:
Trojan Files Found:
C:\WINDOWS\Fonts\Crack.exe - Deleted
C:\WINDOWS\Fonts\*.zip - 1 File(s) 637,944 bytes - Deleted
C:\WINDOWS\Fonts\'\*.zip - 982 File(s) 626,461,990 bytes - Deleted
Folder C:\WINDOWS\Fonts\' - Removed
Removing Temp Files...
ADS Check:
C:\WINDOWS
No streams found.
C:\WINDOWS\system32
No streams found.
C:\WINDOWS\system32\svchost.exe
No streams found.
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.
Final Check:
catchme 0.3.1262.1 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-22 23:56:27
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_UACFLT]
"NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_UACFLT\0000]
"Service"="uacFlt"
"Legacy"=dword:00000001
"ConfigFlags"=dword:00000000
"Class"="LegacyDriver"
"ClassGUID"="{8ECC055D-047F-11D1-A537-0000F8753ED1}"
"DeviceDesc"="Plantronics USB Audio Adapter EQ Filter Driver"
"Capabilities"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Control\Session Manager\Memory Management\PrefetchParameters]
"VideoInitTime"=dword:000010d8
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Control\Watchdog\Display]
"ShutdownCount"=dword:00000566
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\SharedAccess\Epoch]
"Epoch"=dword:00003283
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\SPBBCDrv\Parameters]
"Configuration"="C:\Program Files\Common Files\Symantec Shared\SPBBC\2007-11-21-2c9f.kc"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\Tcpip\Parameters\Interfaces\{00CD4987-2CB7-4631-9C5A-182743264320}]
"LeaseObtainedTime"=dword:47449851
"T1"=dword:47454111
"T2"=dword:4745bfa1
"LeaseTerminatesTime"=dword:4745e9d1
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\wscsvc]
"Start"=dword:00000004
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\{00CD4987-2CB7-4631-9C5A-182743264320}\Parameters\Tcpip]
"LeaseObtainedTime"=dword:47449851
"T1"=dword:47454111
"T2"=dword:4745bfa1
"LeaseTerminatesTime"=dword:4745e9d1
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\Program Files\\World of Warcraft\\WoW-1.7.1.4695-to-1.8.0-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-1.7.1.4695-to-1.8.0-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\WoW-1.8.3.4807-to-1.8.4.4878-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-1.8.3.4807-to-1.8.4.4878-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Documents and Settings\\Frogman\\My Documents\\Downloads\\Arathi_Basin_new_EG-downloader.exe"="C:\\Documents and Settings\\Frogman\\My Documents\\Downloads\\Arathi_Basin_new_EG-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\WoW-1.8.4.4878-to-1.9.0.4937-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-1.8.4.4878-to-1.9.0.4937-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\WoW-1.9.2.4996-to-1.9.3.5059-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-1.9.2.4996-to-1.9.3.5059-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\WoW-1.9.4.5086-to-1.10.0.5195-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-1.9.4.5086-to-1.10.0.5195-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\WINDOWS\\system32\\sessmgr.exe"="C:\\WINDOWS\\system32\\sessmgr.exe:*


"C:\\Documents and Settings\\Frogman\\My Documents\\Downloads\\wow-ptr-downloader2.exe"="C:\\Documents and Settings\\Frogman\\My Documents\\Downloads\\wow-ptr-downloader2.exe:*:Enabled:Blizzard Downloader"
"C:\\Documents and Settings\\Frogman\\My Documents\\Downloads\\WoW-1.10.2.5302-to-0.11.0.5344-enUS-downloader.exe"="C:\\Documents and Settings\\Frogman\\My Documents\\Downloads\\WoW-1.10.2.5302-to-0.11.0.5344-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"="C:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\WoWTest\\WoW-0.11.0.5383-to-0.11.0.5413-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoWTest\\WoW-0.11.0.5383-to-0.11.0.5413-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\WoW-1.10.2.5302-to-1.11.0.5428-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-1.10.2.5302-to-1.11.0.5428-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\WoW-1.11.1.5462-to-1.11.2.5464-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-1.11.1.5462-to-1.11.2.5464-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Documents and Settings\\Frogman\\My Documents\\Downloads\\WoW-1.11.2.5464-to-0.12.0.5496-enUS-downloader.exe"="C:\\Documents and Settings\\Frogman\\My Documents\\Downloads\\WoW-1.11.2.5464-to-0.12.0.5496-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\WoWTest\\WoW-0.12.0.5537-to-0.12.0.5561-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoWTest\\WoW-0.12.0.5537-to-0.12.0.5561-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\StubInstaller.exe"="C:\\StubInstaller.exe:*:Enabled:LimeWire swarmed installer"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\World of Warcraft\\WoW-1.11.2.5464-to-1.12.0.5595-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-1.11.2.5464-to-1.12.0.5595-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Documents and Settings\\Frogman\\My Documents\\Downloads\\WoW-1.12.0.5595-to-0.12.1.5803-enUS-downloader.exe"="C:\\Documents and Settings\\Frogman\\My Documents\\Downloads\\WoW-1.12.0.5595-to-0.12.1.5803-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\WoW-1.12.0.5595-to-1.12.1.5875-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-1.12.0.5595-to-1.12.1.5875-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\Common Files\\AOL\\1152161668\\ee\\aim6.exe"="C:\\Program Files\\Common Files\\AOL\\1152161668\\ee\\aim6.exe:*

"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*

"C:\\Program Files\\Common Files\\AOL\\1152161668\\ee\\aolsoftware.exe"="C:\\Program Files\\Common Files\\AOL\\1152161668\\ee\\aolsoftware.exe:*

"C:\\WINDOWS\\system32\\mmmdajfk.exe"="C:\\WINDOWS\\system32\\mmm"
"C:\\WINDOWS\\system32\\xnfrwhpt.exe"="C:\\WINDOWS\\system32\\xnf"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled

Remaining Files:
---------------
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes:
Wed 4 Aug 2004 93,184 A.SH. --- "C:\Program Files\Internet Explorer\iexplore.exe"
Wed 13 Oct 2004 1,694,208 ..SH. --- "C:\Program Files\Messenger\msmsgs.exe"
Wed 4 Aug 2004 60,416 A.SH. --- "C:\Program Files\Outlook Express\msimn.exe"
Mon 1 Jan 2007 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Thu 25 Jan 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Fri 9 Sep 2005 1,740 A..HR --- "C:\Program Files\Common Files\Symantec Shared\Registry Backup\ccReg.reg"
Fri 9 Sep 2005 274,904 A..HR --- "C:\Program Files\Common Files\Symantec Shared\Registry Backup\CommonClient.reg"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico11.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico12.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico13.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico14.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico15.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico16.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico17.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico18.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico19.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico1A.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico1C.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico1D.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico1E.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico1F.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico20.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico23.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico24.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico25.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico26.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico27.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico28.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico29.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico2A.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico2B.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico2C.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico2D.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico2E.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico2F.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico30.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico31.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico32.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico33.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico34.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico35.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico36.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico37.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico38.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico39.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico3A.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico3B.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico3C.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico3D.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico3E.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico3F.tmp"
Fri 16 Nov 2007 4,286 A..H. --- "C:\Deckard\System Scanner\20071120194750\backup\DOCUME~1\Frogman\LOCALS~1\Temp\ico40.tmp"
Finished!