SDFix: Version 1.240
Run by Valerie on Fri 02/19/2010 at 11:06 PM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Checking Services :
Restoring Default Security Values
Restoring Default Hosts File
Rebooting
Checking Files :
No Trojan Files Found
Removing Temp Files
ADS Check :
Final Check :
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-20 08:47:52
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20]
"RefCount"=dword:00000002
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\WINDOWS\\system32\\dlcjcoms.exe"="C:\\WINDOWS\\system32\\dlcjcoms.exe:*:Enabled:Dell 964 Server"
"C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\dlcjpswx.exe"="C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\dlcjpswx.exe:*:Enabled:Dell 964 Printer Status"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\Intuit\\QuickBooks 2005\\QBDBMgrN.exe"="C:\\Program Files\\Intuit\\QuickBooks 2005\\QBDBMgrN.exe:*:Enabled:QuickBooks 2008 Data Manager"
"C:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"="C:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"
"C:\\Program Files\\Common Files\\Intuit\\Update Service\\IntuitUpdateService.exe"="C:\\Program Files\\Common Files\\Intuit\\Update Service\\IntuitUpdateService.exe:LocalSubNet:Disabled:Intuit Update Shared Downloads Server"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"="C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe:*:Enabled:EasyShare"
"C:\\Program Files\\AVG\\AVG8\\avgam.exe"="C:\\Program Files\\AVG\\AVG8\\avgam.exe:*:Enabled:avgam.exe"
"C:\\Program Files\\AVG\\AVG8\\avgdiag.exe"="C:\\Program Files\\AVG\\AVG8\\avgdiag.exe:*:Enabled:avgdiag.exe"
"C:\\Program Files\\AVG\\AVG8\\avgdiagex.exe"="C:\\Program Files\\AVG\\AVG8\\avgdiagex.exe:*:Enabled:avgdiagex.exe"
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"="C:\\Program Files\\AVG\\AVG8\\avgupd.exe:*:Enabled:avgupd.exe"
"C:\\Program Files\\AVG\\AVG8\\avgnsx.exe"="C:\\Program Files\\AVG\\AVG8\\avgnsx.exe:*:Enabled:avgnsx.exe"
"C:\\Program Files\\AVG\\AVG9\\avgam.exe"="C:\\Program Files\\AVG\\AVG9\\avgam.exe:*:Enabled:avgam.exe"
"C:\\Program Files\\AVG\\AVG9\\avgdiagex.exe"="C:\\Program Files\\AVG\\AVG9\\avgdiagex.exe:*:Enabled:avgdiagex.exe"
"C:\\Program Files\\AVG\\AVG9\\avgupd.exe"="C:\\Program Files\\AVG\\AVG9\\avgupd.exe:*:Enabled:avgupd.exe"
"C:\\Program Files\\AVG\\AVG9\\avgnsx.exe"="C:\\Program Files\\AVG\\AVG9\\avgnsx.exe:*:Enabled:avgnsx.exe"
"C:\\Documents and Settings\\Valerie\\Application Data\\mjusbsp\\magicJack.exe"="C:\\Documents and Settings\\Valerie\\Application Data\\mjusbsp\\magicJack.exe:*:Enabled:magicJack"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"="C:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
Remaining Files :
Files with Hidden Attributes :
Wed 21 Jan 2004 61,440 ...H. --- "C:\Program Files\MSN\msnupdate!@#@.exe"
Wed 21 Jan 2004 292,864 ...H. --- "C:\Program Files\MSN\txsrvc.dll"
Wed 21 Jan 2004 302,080 ...H. --- "C:\Program Files\MSN\unicows.dll"
Sun 20 Jul 2008 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Wed 17 Feb 2010 49,664 ...H. --- "C:\Documents and Settings\Valerie\My Documents\~WRL2543.tmp"
Tue 14 Oct 2008 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp"
Wed 16 Jan 2008 30,208 ...H. --- "C:\Documents and Settings\Valerie\My Documents\Stationary\~WRL0001.tmp"
Wed 9 Dec 2009 32,256 ...H. --- "C:\Documents and Settings\Valerie\My Documents\Stationary\~WRL4002.tmp"
Sun 26 Apr 2009 266,752 ...H. --- "C:\Documents and Settings\Valerie\Application Data\Microsoft\Templates\~WRL0189.tmp"
Fri 10 Jul 2009 172,544 ...H. --- "C:\Documents and Settings\Valerie\Application Data\Microsoft\Word\~WRL0115.tmp"
Wed 25 Nov 2009 585,728 ...H. --- "C:\Documents and Settings\Valerie\Application Data\Microsoft\Word\~WRL0341.tmp"
Fri 22 Jan 2010 712,192 ...H. --- "C:\Documents and Settings\Valerie\Application Data\Microsoft\Word\~WRL0356.tmp"
Tue 8 Sep 2009 367,104 ...H. --- "C:\Documents and Settings\Valerie\Application Data\Microsoft\Word\~WRL2661.tmp"
Tue 6 Oct 2009 428,032 ...H. --- "C:\Documents and Settings\Valerie\Application Data\Microsoft\Word\~WRL2817.tmp"
Sun 2 Aug 2009 271,872 ...H. --- "C:\Documents and Settings\Valerie\Application Data\Microsoft\Word\~WRL2879.tmp"
Wed 24 Jun 2009 134,656 ...H. --- "C:\Documents and Settings\Valerie\Application Data\Microsoft\Word\~WRL3678.tmp"
Fri 10 Apr 2009 725,296 A..H. --- "C:\Documents and Settings\Valerie\Application Data\mjusbsp\ar00000\install.exe"
Fri 10 Apr 2009 6,327,408 A..H. --- "C:\Documents and Settings\Valerie\Application Data\mjusbsp\in00000\setup.exe"
Fri 10 Apr 2009 725,296 A..H. --- "C:\Documents and Settings\Valerie\Application Data\mjusbsp\Upgrade\install1.exe"
Fri 10 Apr 2009 6,327,408 A..H. --- "C:\Documents and Settings\Valerie\Application Data\mjusbsp\Upgrade\setup1.exe"
Sun 20 Jul 2008 4,348 ...H. --- "C:\Documents and Settings\Valerie\My Documents\My Music\License Backup\drmv1key.bak"
Mon 28 Jul 2008 20 ...H. --- "C:\Documents and Settings\Valerie\My Documents\My Music\License Backup\drmv1lic.bak"
Sun 20 Jul 2008 400 ...H. --- "C:\Documents and Settings\Valerie\My Documents\My Music\License Backup\drmv2key.bak"
Mon 28 Jul 2008 1,536 ...H. --- "C:\Documents and Settings\Valerie\My Documents\My Music\License Backup\drmv2lic.bak"
Finished!