Able to completely run SDFix this time.. it rebooted to normal mode. Upon logging in, the SDFix window appeared and finish the process.
SDFix: Version 1.177 Run by User on 2008-04-30 at 10:56 PM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Checking Services :
Name :
MRV47
Path :
MRV47 - Deleted
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting
Checking Files :
Trojan Files Found:
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat - Contains Links to Malware Sites! - Deleted
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat - Contains Links to Malware Sites! - Deleted
C:\Temp\1cb\syscheck.log - Deleted
C:\WINDOWS\system32\sockins32.dll - Deleted
C:\WINDOWS\winself.exe - Deleted
C:\WINDOWS\system32\drivers\MRV47.sys - Deleted
C:\WINDOWS\system32\drivers\MRV47.sys - Deleted
Removing Temp Files
ADS Check :
Final Check :
catchme 0.3.1353.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-04-30 23:03:19
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s0"=dword:4ce74f62
"s1"=dword:1fb8e70e
"s2"=dword:a278c24d
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\BitComet\\BitComet.exe"="C:\\Program Files\\BitComet\\BitComet.exe:*:Enabled:BitComet - a BitTorrent Client"
"C:\\Documents and Settings\\User\\Local Settings\\Temp\\WZSE0.TMP\\SymNRT.exe"="C:\\Documents and Settings\\User\\Local Settings\\Temp\\WZSE0.TMP\\SymNRT.exe:*:Disabled:Symantec Removal Utility"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
Remaining Files :
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes :
Wed 4 Aug 2004 60,416 A.SH. --- "C:\Program Files\Outlook Express\msimn.exe"
Wed 12 Mar 2003 119 A..HR --- "C:\WINDOWS\system32\NTICDMK32.dll"
Tue 26 Mar 2002 1,024 A..HR --- "C:\WINDOWS\system32\ntiembed.dll"
Tue 22 Apr 2008 145,920 ..SHR --- "C:\Program Files\BillP Studios\WinPatrol\Setup.exe"
Wed 7 Mar 2001 311,296 A..HR --- "C:\WINDOWS\system32\Tools\AC2K.exe"
Tue 20 Feb 2001 310,784 A..HR --- "C:\WINDOWS\system32\Tools\AC98.exe"
Tue 20 Feb 2001 311,296 A..HR --- "C:\WINDOWS\system32\Tools\ACL98.exe"
Tue 20 Feb 2001 311,808 A..HR --- "C:\WINDOWS\system32\Tools\ACLME.exe"
Fri 27 Apr 2001 327,168 A..HR --- "C:\WINDOWS\system32\Tools\All.exe"
Thu 23 Nov 2000 316,416 A..HR --- "C:\WINDOWS\system32\Tools\AutoClick.exe"
Tue 16 Oct 2001 363,008 A..HR --- "C:\WINDOWS\system32\Tools\Change.exe"
Wed 10 Apr 2002 547,840 A..HR --- "C:\WINDOWS\system32\Tools\CheckPath.exe"
Thu 30 Aug 2001 381,440 A..HR --- "C:\WINDOWS\system32\Tools\Counter.exe"
Sun 20 Jan 2002 360,960 A..HR --- "C:\WINDOWS\system32\Tools\DelDv.exe"
Mon 19 Mar 2001 532,480 A..HR --- "C:\WINDOWS\system32\Tools\DeleteFiles.exe"
Sun 20 Jan 2002 360,960 A..HR --- "C:\WINDOWS\system32\Tools\DelT2.exe"
Sun 20 Jan 2002 360,960 A..HR --- "C:\WINDOWS\system32\Tools\DelT2Dv.exe"
Wed 6 Mar 2002 360,960 A..HR --- "C:\WINDOWS\system32\Tools\DelTools.exe"
Mon 11 Mar 2002 361,472 A..HR --- "C:\WINDOWS\system32\Tools\LostRun.exe"
Mon 2 Apr 2001 296,960 A..HR --- "C:\WINDOWS\system32\Tools\RegClean.exe"
Thu 7 Mar 2002 369,152 A..HR --- "C:\WINDOWS\system32\Tools\Regexe.exe"
Thu 7 Mar 2002 382,464 A..HR --- "C:\WINDOWS\system32\Tools\Restart.exe"
Thu 7 Mar 2002 374,784 A..HR --- "C:\WINDOWS\system32\Tools\RunAP.exe"
Thu 7 Mar 2002 360,960 A..HR --- "C:\WINDOWS\system32\Tools\RunRegexe.exe"
Fri 2 Nov 2001 379,392 A..HR --- "C:\WINDOWS\system32\Tools\SDW98ME.exe"
Fri 9 Mar 2001 312,832 A..HR --- "C:\WINDOWS\system32\Tools\SoundDrv.exe"
Fri 12 Nov 2004 37,376 ...H. --- "C:\Program Files\Common Files\Adobe\ESD\DLMCleanup.exe"
Wed 30 Apr 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\ab59ac72525ea90a47679441587835c9\BIT2.tmp"
Mon 26 Jun 2006 273,920 ...H. --- "C:\Documents and Settings\User\My Documents\My Works\Career\~WRL0003.tmp"
Mon 2 Oct 2006 632,832 ...H. --- "C:\Documents and Settings\User\My Documents\My Works\Career\~WRL0701.tmp"
Mon 2 Oct 2006 111,104 ...H. --- "C:\Documents and Settings\User\My Documents\My Works\Career\~WRL1421.tmp"
Sun 29 Oct 2006 1,031,680 ...H. --- "C:\Documents and Settings\User\My Documents\My Works\Career\~WRL1530.tmp"
Mon 2 Oct 2006 419,840 ...H. --- "C:\Documents and Settings\User\My Documents\My Works\Career\~WRL1910.tmp"
Mon 2 Oct 2006 210,432 ...H. --- "C:\Documents and Settings\User\My Documents\My Works\Career\~WRL2468.tmp"
Mon 2 Oct 2006 312,832 ...H. --- "C:\Documents and Settings\User\My Documents\My Works\Career\~WRL2915.tmp"
Mon 2 Oct 2006 70,144 ...H. --- "C:\Documents and Settings\User\My Documents\My Works\Career\~WRL3288.tmp"
Mon 2 Oct 2006 532,992 ...H. --- "C:\Documents and Settings\User\My Documents\My Works\Career\~WRL3469.tmp"
Finished!