.....and here is SDfix log
SDFix: Version 1.119
Run by Owner on Wed 12/26/2007 at 09:53 PM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting...
Normal Mode:
Checking Files:
Trojan Files Found:
C:\Documents and Settings\Owner\Desktop\Error Cleaner.url - Deleted
C:\Documents and Settings\Owner\Favorites\Error Cleaner.url - Deleted
C:\Documents and Settings\Owner\Desktop\Privacy Protector.url - Deleted
C:\Documents and Settings\Owner\Favorites\Privacy Protector.url - Deleted
C:\Documents and Settings\Owner\Desktop\Spyware&Malware Protection.url - Deleted
C:\Documents and Settings\Owner\Favorites\Spyware&Malware Protection.url - Deleted
C:\autorun.inf - Deleted
C:\WINDOWS\alxvdvm.dll - Deleted
C:\WINDOWS\bvtqfvx.dll - Deleted
C:\WINDOWS\dat.txt - Deleted
C:\WINDOWS\domnftwmnf.dll - Deleted
C:\WINDOWS\emlkdvo.dll - Deleted
C:\WINDOWS\fvkwdrt.exe - Deleted
C:\WINDOWS\rs.txt - Deleted
Removing Temp Files...
ADS Check:
C:\WINDOWS
No streams found.
C:\WINDOWS\system32
No streams found.
C:\WINDOWS\system32\svchost.exe
No streams found.
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.
Final Check:
catchme 0.3.1333.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-12-26 22:08:59
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\System]
"OODEFRAG08.00.00.01WORKSTATION"="FB4307C6B06AAEB20C870D38DEA5C0760DF956084B29BE3048F3AADB90075445E01A868848A0CA0D342BA4FBD942BB3D9061D6AB944C12EB3B6BAC271DF0D8193FE86DA22CFADED31BFDE02795A921602CF866C02B1C1300F700DDCCE4CB29373F5960C8DD93BB3065B5CAC0234F382B1F9D92BDCD051F797D58EFD3EF1BD58A3C77D6B3D328C911EA67BFD0844BDB2C608BBE1DAA16A4A57EF9EBC9BC888444C4371D1FF89A01A6B90DEFE63056FAB31A689EDDE683FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C8EDD5E5BE2F6E6675D575E7D6A3B9808A9C6AECB7A5D14078EDD5E5BE2F6E66718095FDBB90CE9C1C5A93ED50294881A0856E53F715D9A0BF335367FB6258023CEAC5C6A4F8EF82BBCD5849F5E1C3950C273E28058325B61968A0232F5B0201440F6EB2D8096F1E689209EE3E93A4883BD344EF2B40F50BE3EFA7AE0AE7E6E23DC30D2F6F449048790F1ED20CF05123D75C2C659591B21491D131C39F9E501ACABE58A7E2BD0D245CEFA86B213176730F98C20DEEC02EAC877A1174D4243E1B4476A3EDC725B74F9D32DB35E89100C2DEF47DF0EE9733F2B273CCD9349F70F5FDCD05091EF9974A5C13E71CBDB12B72F8E693F589FA3230019BA57E2A068FB76B0F452FD9D4151E95127738589C3165024AC2F91AFC90F7D4F3801FAAF7D0EE896F00FE9C60C7F0E4B291CFA63CF48508E1350F19121EFFB5E1549FB35249DC8FAA802FD0C38647D114388000F65E114C35C7917906928F7EF76636ABD4C7A4BDA3F5DCA6486DCC6163E03CB0736EAA34B12B67F4BE68B134144B732306B664A481E0441163D359C60220F7A97785FA9C0FEC4903361E391242A611FC17897C3EAF38EB7BEA5B3578CBDE10AE4E72FF65632181311A36CDCFC982FE27F7237D9FB31CA69CF8D8C6FC7A3E35EE2C3BDFECE7E5433FD7E5882C4432592C7D8E3D1C90AB7F28D47EC05582AB4BFDB4D645B037A5601E9C34CB18923FBA7D030AE9637788A5910A772DB926A24586D4C6EC45F02AC71974DDF416C739D0020809F353A392B824588305963C3B7B80A0B9C1DE23518DC1D75A1A723B5AADC92582F615C4EB7B66DC72E894AD62AD376D6A068247590FDE41C9284762DF563D7464BED3E7C7F269DC6661BD88B6800CD84A54E496B40F7AE2526974361071DF3E057D70F4C86623E6A48DFB70B93FA7C69461A1080864D0E7747447B2099783D3E283A170B07638B1EB6CF23C301E1C4E0913DC76574676600D11624779DC4E17E08D9304B6C81984F890668E73BB9BBC88D49D48C511276AC97B8D63DB538DFBFB59947DFD7FB47ED0B41EA6D7FE84D843178B0AD187CCBF25D7CC0093AED8BA6E106E1649CF55271FAE3A30FBFBA3579E7A565C3F4BE47C85B5723B6"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\\n0\x152[\x17d\26NLuMQ9\x8dHr\v0]
"Order"=hex:08,00,00,00,02,00,00,00,04,01,00,00,01,00,00,00,02,00,00,00,7a,..
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{C0A5D735-D056-B06A-4A00-0C1BBE81A98C}]
"iaifhacomgppaakemb"=hex:6a,61,6c,66,62,6d,6e,6e,6f,63,68,62,61,69,6c,66,6d,69,6d,6e,00,..
"haghfofolieimcbd"=hex:6b,61,64,67,6b,65,64,70,6c,69,67,63,66,64,69,65,6a,61,64,65,6f,..
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{D18AE723-B919-4785-490F-E2034FA24ADD}]
"eagninegpl"=hex:66,61,69,6e,66,6f,69,6c,6b,6b,64,6d,00,fc
"dabofnpf"=hex:64,62,63,61,70,64,6c,68,6d,69,6c,6b,61,65,6f,6c,68,63,6b,70,63,..
"iaopjflmkjieflcknn"=hex:6a,61,6c,61,70,66,67,61,6c,64,6b,68,64,69,68,6f,70,64,6c,63,00,..
"haaapofampddgohl"=hex:6a,61,6c,61,70,66,67,61,6c,64,6b,68,64,69,68,6f,70,64,6c,63,00,..
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled
xpsp2res.dll,-22019"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
"C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader"
"C:\\Program Files\\Common Files\\AOL\\1133279849\\ee\\aolsoftware.exe"="C:\\Program Files\\Common Files\\AOL\\1133279849\\ee\\aolsoftware.exe:*:Enabled:AOL Services"
"C:\\Program Files\\Common Files\\AOL\\1133279849\\ee\\aim6.exe"="C:\\Program Files\\Common Files\\AOL\\1133279849\\ee\\aim6.exe:*:Enabled:AIM"
"C:\\Program Files\\Paltalk Messenger\\paltalk.exe"="C:\\Program Files\\Paltalk Messenger\\paltalk.exe:*:Enabled
altalk Messenger 8.1"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\Sony\\Station\\Launchpad\\LaunchPad.exe"="C:\\Program Files\\Sony\\Station\\Launchpad\\LaunchPad.exe:*:Enabled:LaunchPad"
"C:\\Program Files\\Softnyx\\Rakion\\Bin\\Rakion.bin"="C:\\Program Files\\Softnyx\\Rakion\\Bin\\Rakion.bin:*:Enabled:Rakion"
"C:\\Program Files\\DAP\\DAP.exe"="C:\\Program Files\\DAP\\DAP.exe:*:Enabled
ownload Accelerator Plus (DAP)"
"C:\\Program Files\\Phoenix Games Studio\\Fung Wan Online\\FWOnline.exe"="C:\\Program Files\\Phoenix Games Studio\\Fung Wan Online\\FWOnline.exe:*:Enabled:FWOnline"
"C:\\Program Files\\VitalSign_IGO\\updater.exe"="C:\\Program Files\\VitalSign_IGO\\updater.exe:*:Enabled:delay"
"C:\\Program Files\\Turbine\\Dungeons & Dragons Online - Stormreach\\dndclient.exe"="C:\\Program Files\\Turbine\\Dungeons & Dragons Online - Stormreach\\dndclient.exe:*:Enabled:dndclient"
"C:\\Program Files\\GameSpy Arcade\\Aphex.exe"="C:\\Program Files\\GameSpy Arcade\\Aphex.exe:*:Enabled:GameSpy Arcade"
"C:\\Program Files\\Serious Sam 2 Demo\\Bin\\Sam2.exe"="C:\\Program Files\\Serious Sam 2 Demo\\Bin\\Sam2.exe:*
isabled:Sam2"
"C:\\Program Files\\Codemasters\\RF Online\\RF.exe"="C:\\Program Files\\Codemasters\\RF Online\\RF.exe:*:Enabled:RFLauncher"
"C:\\Program Files\\BitComet\\BitComet.exe"="C:\\Program Files\\BitComet\\BitComet.exe:*:Enabled:BitComet - a BitTorrent Client"
"C:\\Program Files\\Cabal_ENG\\update\\ESTdnheadless.exe"="C:\\Program Files\\Cabal_ENG\\update\\ESTdnheadless.exe:*:Enabled:EST! download engine"
"C:\\StubInstaller.exe"="C:\\StubInstaller.exe:*:Enabled:LimeWire swarmed installer"
"C:\\Program Files\\Morpheus\\Morpheus.exe"="C:\\Program Files\\Morpheus\\Morpheus.exe:*:Enabled:M5Shell"
"C:\\Program Files\\Kazaa\\kazaa.exe"="C:\\Program Files\\Kazaa\\kazaa.exe:*:Enabled:Kazaa"
"C:\\Program Files\\World of Warcraft\\WoW-1.11.1.5462-to-1.11.2.5464-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-1.11.1.5462-to-1.11.2.5464-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\MAIET\\Gunz\\GunzLauncher.exe"="C:\\Program Files\\MAIET\\Gunz\\GunzLauncher.exe:*:Enabled:GunzLauncher"
"C:\\Program Files\\MAIET\\Gunz\\Gunz.exe"="C:\\Program Files\\MAIET\\Gunz\\Gunz.exe:*:Enabled:Gunz"
"C:\\Program Files\\ZipTorrent\\ZipTorrent.exe"="C:\\Program Files\\ZipTorrent\\ZipTorrent.exe:*:Enabled:ZipTorrent Application"
"C:\\WINDOWS\\system32\\dpvsetup.exe"="C:\\WINDOWS\\system32\\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\\WINDOWS\\system32\\rundll32.exe"="C:\\WINDOWS\\system32\\rundll32.exe:*:Enabled:Run a DLL as an App"
"C:\\Program Files\\Chrome MP Demo 2004\\ChromeNet.exe"="C:\\Program Files\\Chrome MP Demo 2004\\ChromeNet.exe:*:Enabled:Chrome"
"C:\\Alien Arena 2007\\crx.exe"="C:\\Alien Arena 2007\\crx.exe:*:Enabled:crx"
"C:\\Program Files\\NAMCO BANDAI Games\\Warhammer Mark of Chaos DEMO\\Warhammer_DEMO.exe"="C:\\Program Files\\NAMCO BANDAI Games\\Warhammer Mark of Chaos DEMO\\Warhammer_DEMO.exe:*:Enabled:Warhammerr: Mark of ChaosT Single Player Demo"
"C:\\Program Files\\Ubisoft\\Demo\\Ghost Recon Advanced Warfighter Demo\\GRAW_demo.exe"="C:\\Program Files\\Ubisoft\\Demo\\Ghost Recon Advanced Warfighter Demo\\GRAW_demo.exe:*:Enabled:GRAW_demo"
"C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe:*:Enabled:avginet.exe"
"C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe:*:Enabled:avgamsvr.exe"
"C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe:*:Enabled:avgcc.exe"
"C:\\Program Files\\Grisoft\\AVG Free\\avgemc.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgemc.exe:*:Enabled:avgemc.exe"
"C:\\Program Files\\Ubisoft\\Red Storm Entertainment\\Rainbow Six Lockdown Demo\\Lockdown.exe"="C:\\Program Files\\Ubisoft\\Red Storm Entertainment\\Rainbow Six Lockdown Demo\\Lockdown.exe:*:Enabled:Lockdown"
"C:\\Program Files\\infinity_eng\\xclient.exe"="C:\\Program Files\\infinity_eng\\xclient.exe:*:Enabled:xclient"
"C:\\Program Files\\Sierra\\FEAR MP Demo\\FEARServer.exe"="C:\\Program Files\\Sierra\\FEAR MP Demo\\FEARServer.exe:*:Enabled:F.E.A.R. MP Demo Dedicated Server"
"C:\\Program Files\\Sierra\\FEAR MP Demo\\Config.exe"="C:\\Program Files\\Sierra\\FEAR MP Demo\\Config.exe:*:Enabled:F.E.A.R. MP Demo Configuration Utility"
"C:\\Program Files\\Monte Cristo\\Silverfall Demo\\Silverfall.exe"="C:\\Program Files\\Monte Cristo\\Silverfall Demo\\Silverfall.exe:*:Enabled:Silverfall"
"C:\\Program Files\\Turbine\\The Lord of the Rings Online\\lotroclient.exe"="C:\\Program Files\\Turbine\\The Lord of the Rings Online\\lotroclient.exe:*:Enabled:lotroclient"
"C:\\Program Files\\Ubisoft\\Demo\\Techland\\Call of Juarez MP Demo\\CoJMPdemo.exe"="C:\\Program Files\\Ubisoft\\Demo\\Techland\\Call of Juarez MP Demo\\CoJMPdemo.exe:*:Enabled:ChromeEngine3"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\Program Files\\AIM\\aim.exe"="C:\\Program Files\\AIM\\aim.exe:*:Enabled:AOL Instant Messenger"
"C:\\Documents and Settings\\Owner\\My Documents\\My Completed Downloads\\wowclient-downloader.exe"="C:\\Documents and Settings\\Owner\\My Documents\\My Completed Downloads\\wowclient-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\WoW-1.12.0-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-1.12.0-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\WoW-1.12.x-to-2.0.1-enUS-patch-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-1.12.x-to-2.0.1-enUS-patch-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\WINDOWS\\system32\\dpnsvr.exe"="C:\\WINDOWS\\system32\\dpnsvr.exe:*:Enabled:Microsoft DirectPlay8 Server"
"C:\\Program Files\\Starbreeze Studios\\Knights Of The Temple Demo\\Templar.exe"="C:\\Program Files\\Starbreeze Studios\\Knights Of The Temple Demo\\Templar.exe:*:Enabled:Templar"
"C:\\Program Files\\Fury\\Binaries\\LauncherApp.exe"="C:\\Program Files\\Fury\\Binaries\\LauncherApp.exe:*:Enabled:LauncherApp"
"C:\\Program Files\\Metin2_UK\\metin2.bin"="C:\\Program Files\\Metin2_UK\\metin2.bin:*:Enabled:metin2"
"C:\\Program Files\\Silent Grove Studios\\Dawnspire\\Dawnspire.exe"="C:\\Program Files\\Silent Grove Studios\\Dawnspire\\Dawnspire.exe:*:Enabled
awnspire"
"C:\\Program Files\\NGD Studios\\Regnum Online\\LiveServer\\ROClientGame.exe"="C:\\Program Files\\NGD Studios\\Regnum Online\\LiveServer\\ROClientGame.exe:*:Enabled:RegnumOnline"
"C:\\Program Files\\NAMCO BANDAI Games\\Mage Knight(TM) Apocalypse\\MageKnight.exe"="C:\\Program Files\\NAMCO BANDAI Games\\Mage Knight(TM) Apocalypse\\MageKnight.exe:*:Enabled:MageKnight"
"C:\\Program Files\\NAMCO BANDAI Games\\Mage Knight(TM) Apocalypse\\update.exe"="C:\\Program Files\\NAMCO BANDAI Games\\Mage Knight(TM) Apocalypse\\update.exe:*:Enabled:Auto Update "
"C:\\Program Files\\WEBZEN\\Soul of the Ultimate Nation\\VMModule._ex"="C:\\Program Files\\WEBZEN\\Soul of the Ultimate Nation\\VMModule._ex:*
isabled:AA" A«¬§A’A"
"C:\\Documents and Settings\\Owner\\Local Settings\\Temporary Internet Files\\Content.IE5\\X2S06NW5\\wowclient-downloader[1].exe"="C:\\Documents and Settings\\Owner\\Local Settings\\Temporary Internet Files\\Content.IE5\\X2S06NW5\\wowclient-downloader[1].exe:*:Enabled:Blizzard Downloader"
"C:\\Documents and Settings\\Owner\\Local Settings\\Temp\\Temporary Internet Files\\Content.IE5\\ZXDFA2AP\\WoW-BurningCrusade-enUS-Installer-downloader[1].exe"="C:\\Documents and Settings\\Owner\\Local Settings\\Temp\\Temporary Internet Files\\Content.IE5\\ZXDFA2AP\\WoW-BurningCrusade-enUS-Installer-downloader[1].exe:*:Enabled:Blizzard Downloader"
"C:\\Documents and Settings\\Owner\\Local Settings\\Temp\\nslA5.tmp\\utorrent.exe"="C:\\Documents and Settings\\Owner\\Local Settings\\Temp\\nslA5.tmp\\utorrent.exe:*:Enabled:æTorrent"
"C:\\Program Files\\BitTorrent_DNA\\dna.exe"="C:\\Program Files\\BitTorrent_DNA\\dna.exe:*:Enabled:BitTorrent DNA"
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\\Program Files\\PlayOnline\\SquareEnix\\PlayOnlineViewer\\pol.exe"="C:\\Program Files\\PlayOnline\\SquareEnix\\PlayOnlineViewer\\pol.exe:*:Enabled
layOnline Viewer"
"C:\\Program Files\\Guild Wars\\Gw.exe"="C:\\Program Files\\Guild Wars\\Gw.exe:*:Enabled:Guild Wars"
"C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:æTorrent"
"C:\\WINDOWS\\system32\\PnkBstrA.exe"="C:\\WINDOWS\\system32\\PnkBstrA.exe:*:Enabled
nkBstrA"
"C:\\WINDOWS\\system32\\PnkBstrB.exe"="C:\\WINDOWS\\system32\\PnkBstrB.exe:*:Enabled
nkBstrB"
"C:\\Program Files\\Immortals Online\\Immortals.exe"="C:\\Program Files\\Immortals Online\\Immortals.exe:*:Enabled:Immortals"
"C:\\UT2004Demo\\System\\UT2004.exe"="C:\\UT2004Demo\\System\\UT2004.exe:*:Enabled:UT2004"
"C:\\Program Files\\Unreal Tournament 3 Demo\\Binaries\\UT3Demo.exe"="C:\\Program Files\\Unreal Tournament 3 Demo\\Binaries\\UT3Demo.exe:*:Enabled:Unreal Tournament 3 Demo"
"C:\\ijji\\ENGLISH\\u_skid.exe"="C:\\ijji\\ENGLISH\\u_skid.exe:*:Enabled:<ijji Downloader>"
"C:\\Program Files\\AeriaGames\\ProjectTorque\\ProjectTorque.bin"="C:\\Program Files\\AeriaGames\\ProjectTorque\\ProjectTorque.bin:*:Enabled:LevelR"
"C:\\Program Files\\Talisman\\game.exe"="C:\\Program Files\\Talisman\\game.exe:*:Enabled:Talisman online"
"C:\\Program Files\\DriftCity\\DriftCity.exe"="C:\\Program Files\\DriftCity\\DriftCity.exe:*:Enabled
riftCity"
"C:\\Program Files\\NCsoft\\Exteel\\System\\Exteel.exe"="C:\\Program Files\\NCsoft\\Exteel\\System\\Exteel.exe:*:Enabled:Exteel"
"C:\\Documents and Settings\\Owner\\Local Settings\\Temp\\nse1B.tmp\\utorrent.exe"="C:\\Documents and Settings\\Owner\\Local Settings\\Temp\\nse1B.tmp\\utorrent.exe:*:Enabled:æTorrent"
"C:\\Program Files\\Flagship Studios\\Mythos\\bin\\Mythos.exe"="C:\\Program Files\\Flagship Studios\\Mythos\\bin\\Mythos.exe:*:Enabled:Mythos"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled
xpsp2res.dll,-22019"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
"C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Enabled:AOL"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\Program Files\\NCsoft\\Exteel\\System\\Exteel.exe"="C:\\Program Files\\NCsoft\\Exteel\\System\\Exteel.exe:*:Enabled:Exteel"
Remaining Files:
---------------
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes:
--- 4,263 ..SH. --- "C:\WINDOWS\windllreg1c.sys"
Fri 23 Dec 2005 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Mon 26 Feb 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Wed 26 Dec 2007 85,946 A..H. --- "C:\Documents and Settings\Owner\Local Settings\Temp\BIT14.tmp"
Wed 26 Dec 2007 85,946 A..H. --- "C:\Documents and Settings\Owner\Local Settings\Temp\BIT3.tmp"
Wed 26 Dec 2007 0 A..H. --- "C:\Documents and Settings\Owner\Local Settings\Temp\BIT4.tmp"
Wed 26 Dec 2007 85,946 A..H. --- "C:\Documents and Settings\Owner\Local Settings\Temp\BIT9.tmp"
Wed 26 Dec 2007 85,946 A..H. --- "C:\Documents and Settings\Owner\Local Settings\Temp\BITC.tmp"
Wed 26 Dec 2007 0 A..H. --- "C:\Documents and Settings\Owner\Local Settings\Temp\BITD.tmp"
Wed 21 Nov 2007 1,776 ...HR --- "C:\Documents and Settings\Owner\Application Data\SecuROM\UserData\securom_v7_01.bak"
Finished!