Ok here's the SDfix scan in two parts - the Hijackthis scan to follow. Part1 of SDfix:
SDFix: Version 1.240 Run by Jon on Mon 07/20/2009 at 10:54 PM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Checking Services :
Restoring Default Security Values
Restoring Default Hosts File
Rebooting
Checking Files :
No Trojan Files Found
Removing Temp Files
ADS Check :
Final Check :
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-07-20 23:47:47
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
"C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Enabled:America Online 9.0"
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader"
"C:\\Program Files\\Common Files\\AOL\\1137564882\\ee\\aolsoftware.exe"="C:\\Program Files\\Common Files\\AOL\\1137564882\\ee\\aolsoftware.exe:*:Enabled:AOL Services"
"C:\\Program Files\\Common Files\\AOL\\1137564882\\ee\\aim6.exe"="C:\\Program Files\\Common Files\\AOL\\1137564882\\ee\\aim6.exe:*:Enabled:AIM"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe:*:Enabled:hpofxm08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe:*:Enabled:hposfx08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe:*:Enabled:hposid01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe:*:Enabled:hpqcopy.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe:*:Enabled:hpfccopy.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe:*:Enabled:hpqphunl.exe"
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe:*:Enabled:hpqdia.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe:*:Enabled:hpoews01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe:*:Enabled:hpqnrs08.exe"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Last.fm\\LastFM.exe"="C:\\Program Files\\Last.fm\\LastFM.exe:*:Enabled:Last.fm"
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\AIM6\\aim6.exe"="C:\\Program Files\\AIM6\\aim6.exe:*:Enabled:AIM"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
"C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Enabled:America Online 9.0"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
Remaining Files :
Files with Hidden Attributes :
Wed 1 Sep 2004 54,384 A..H. --- "C:\Program Files\America Online 9.0\aolphx.exe"
Wed 1 Sep 2004 156,784 A..H. --- "C:\Program Files\America Online 9.0\aoltray.exe"
Wed 1 Sep 2004 31,344 A..H. --- "C:\Program Files\America Online 9.0\RBM.exe"
Mon 26 Jan 2009 1,740,632 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe"
Mon 26 Jan 2009 5,365,592 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
Tue 1 Nov 2005 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Sat 27 Jun 2009 145,920 ..SHR --- "C:\Program Files\BillP Studios\WinPatrol\Setup.exe"
Sat 19 Apr 2008 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp"
Mon 29 Oct 2007 822 A..H. --- "C:\Program Files\Common Files\AOL\IPHSend\IPH.BAK"
Fri 19 Mar 2004 67,944 ...H. --- "C:\Program Files\Simple Star\PhotoShow Deluxe 3\data\PhotoShow Express.exe"
Mon 16 Apr 2007 286,720 ...H. --- "C:\Documents and Settings\Jon\Application Data\Microsoft\Word\~WRL0812.tmp"
Thu 22 Mar 2007 127,488 ...H. --- "C:\Documents and Settings\Jon\Application Data\Microsoft\Word\~WRL1880.tmp"
Mon 16 Apr 2007 180,224 ...H. --- "C:\Documents and Settings\Jon\Application Data\Microsoft\Word\~WRL2838.tmp"
Wed 4 Oct 2006 3,072,000 A..H. --- "C:\Documents and Settings\Jon\Application Data\U3\temp\Launchpad Removal.exe"
Tue 1 Nov 2005 4,348 ...H. --- "C:\Documents and Settings\Jon\My Documents\My Music\License Backup\drmv1key.bak"
Tue 1 Nov 2005 20 A..H. --- "C:\Documents and Settings\Jon\My Documents\My Music\License Backup\drmv1lic.bak"
Tue 25 Oct 2005 312 A.SH. --- "C:\Documents and Settings\Jon\My Documents\My Music\License Backup\drmv2key.bak"
Wed 27 Jun 2007 31,744 ...H. --- "C:\Documents and Settings\Jon\My Documents\My Documents\Word Documents\~WRL1906.tmp"
Thu 11 Mar 2004 28,160 A..H. --- "C:\Documents and Settings\Jon\My Documents\My Documents\Word Documents_old\World Civ 2004\~WRL0065.tmp"
Fri 27 Feb 2004 24,576 A..H. --- "C:\Documents and Settings\Jon\My Documents\My Documents\Word Documents_old\World Civ 2004\~WRL0172.tmp"
Thu 11 Mar 2004 26,624 A..H. --- "C:\Documents and Settings\Jon\My Documents\My Documents\Word Documents_old\World Civ 2004\~WRL0465.tmp"
Thu 11 Mar 2004 24,576 A..H. --- "C:\Documents and Settings\Jon\My Documents\My Documents\Word Documents_old\World Civ 2004\~WRL0511.tmp"
Tue 9 Mar 2004 25,600 A..H. --- "C:\Documents and Settings\Jon\My Documents\My Documents\Word Documents_old\World Civ 2004\~WRL0543.tmp"
Fri 27 Feb 2004 27,648 A..H. --- "C:\Documents and Settings\Jon\My Documents\My Documents\Word Documents_old\World Civ 2004\~WRL0551.tmp"
Fri 27 Feb 2004 27,136 A..H. --- "C:\Documents and Settings\Jon\My Documents\My Documents\Word Documents_old\World Civ 2004\~WRL0558.tmp"
Fri 27 Feb 2004 27,648 A..H. --- "C:\Documents and Settings\Jon\My Documents\My Documents\Word Documents_old\World Civ 2004\~WRL0653.tmp"
Sun 15 Feb 2004 31,744 A..H. --- "C:\Documents and Settings\Jon\My Documents\My Documents\Word Documents_old\World Civ 2004\~WRL0687.tmp"
Sat 3 Jul 2004 24,064 A..H. --- "C:\Documents and Settings\Jon\My Documents\My Documents\Word Documents_old\World Civ 2004\~WRL0885.tmp"
Fri 27 Feb 2004 26,112 A..H. --- "C:\Documents and Settings\Jon\My Documents\My Documents\Word Documents_old\World Civ 2004\~WRL1123.tmp"
Fri 27 Feb 2004 28,672 A..H. --- "C:\Documents and Settings\Jon\My Documents\My Documents\Word Documents_old\World Civ 2004\~WRL1300.tmp"
Tue 15 Jun 2004 29,696 A..H. --- "C:\Documents and Settings\Jon\My Documents\My Documents\Word Documents_old\World Civ 2004\~WRL1311.tmp"
Fri 27 Feb 2004 24,576 A..H. --- "C:\Documents and Settings\Jon\My Documents\My Documents\Word Documents_old\World Civ 2004\~WRL1443.tmp"
Sun 14 Mar 2004 27,648 A..H. --- "C:\Documents and Settings\Jon\My Documents\My Documents\Word Documents_old\World Civ 2004\~WRL1453.tmp"
Sun 15 Feb 2004 23,552 A..H. --- "C:\Documents and Settings\Jon\My Documents\My Documents\Word Documents_old\World Civ 2004\~WRL1588.tmp"
Fri 27 Feb 2004 25,600 A..H. --- "C:\Documents and Settings\Jon\My Documents\My Documents\Word Documents_old\World Civ 2004\~WRL2060.tmp"
Thu 11 Mar 2004 24,576 A..H. --- "C:\Documents and Settings\Jon\My Documents\My Documents\Word Documents_old\World Civ 2004\~WRL2078.tmp"
Wed 7 Jul 2004 25,088 A..H. --- "C:\Documents and Settings\Jon\My Documents\My Documents\Word Documents_old\World Civ 2004\~WRL2134.tmp"
Thu 11 Mar 2004 26,112 A..H. --- "C:\Documents and Settings\Jon\My Documents\My Documents\Word Documents_old\World Civ 2004\~WRL2194.tmp"
Tue 15 Jun 2004 27,136 A..H. --- "C:\Documents and Settings\Jon\My Documents\My Documents\Word Documents_old\World Civ 2004\~WRL2329.tmp"
Fri 27 Feb 2004 24,576 A..H. --- "C:\Documents and Settings\Jon\My Documents\My Documents\Word Documents_old\World Civ 2004\~WRL2413.tmp"
Thu 11 Mar 2004 24,576 A..H. --- "C:\Documents and Settings\Jon\My Documents\My Documents\Word Documents_old\World Civ 2004\~WRL2429.tmp"