here is my SDfix log:
SDFix: Version 1.240 Run by Compaq_Administrator on Sun 01/11/2009 at 06:10 PM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDfix
Checking Services :
Restoring Default Security Values
Restoring Default Hosts File
Rebooting
Checking Files :
Trojan Files Found:
C:\autorun.inf - Deleted
C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\TMP10.tmp - Deleted
C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\TMP11.tmp - Deleted
C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\TMP12.tmp - Deleted
C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\TMP13.tmp - Deleted
C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\TMP14.tmp - Deleted
C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\TMP15.tmp - Deleted
C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\TMP16.tmp - Deleted
C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\TMP17.tmp - Deleted
C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\TMP18.tmp - Deleted
C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\TMP19.tmp - Deleted
C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\TMP1A.tmp - Deleted
C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\TMP1B.tmp - Deleted
C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\TMP1C.tmp - Deleted
C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\TMP1D.tmp - Deleted
C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\TMP1E.tmp - Deleted
C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\TMP1F.tmp - Deleted
C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\TMP20.tmp - Deleted
C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\TMP21.tmp - Deleted
C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\TMP22.tmp - Deleted
C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\TMP24.tmp - Deleted
C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\TMP27.tmp - Deleted
C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\TMPB.tmp - Deleted
C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\TMPC.tmp - Deleted
C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\TMPD.tmp - Deleted
C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\TMPE.tmp - Deleted
C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\tmpE6.tmp - Deleted
C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\TMPF.tmp - Deleted
C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\tmpF2.tmp - Deleted
C:\WINDOWS\system32\a.exe - Deleted
Folder C:\Documents and Settings\Compaq_Administrator\Application Data\gadcom - Removed
Removing Temp Files
ADS Check :
Final Check :
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-01-11 18:36:18
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{5983294C-6124-4DDC-91E4-0AAACD643268}]
"oaelneemkkhhleefocbmnhlhnimjek"=hex:64,61,65,66,6e,63,6c,6e,00,70
"oaaofomegplghchenbbiipfafcjklb"=hex:6a,61,65,66,6e,63,63,6f,68,6e,62,64,62,70,6a,70,6b,62,62,6b,00,..
"naondekebdnlmdeebknfjhabbekm"=hex:6a,61,68,66,6e,63,6b,6b,6b,70,65,61,67,61,66,6f,66,6d,6b,63,00,..
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Compaq Connections\\6750491\\Program\\Compaq Connections.exe"="C:\\Program Files\\Compaq Connections\\6750491\\Program\\Compaq Connections.exe:*:Enabled:BackWeb for Presario"
"C:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"="C:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe:*:Enabled:Earthlink"
"C:\\Program Files\\BitTornado\\btdownloadgui.exe"="C:\\Program Files\\BitTornado\\btdownloadgui.exe:*:Enabled:btdownloadgui"
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"="C:\\Program Files\\Real\\RealPlayer\\realplay.exe:*:Enabled:RealPlayer"
"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"="C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE:*:Enabled:Internet Explorer"
"C:\\Program Files\\Google\\Google Talk\\googletalk.exe"="C:\\Program Files\\Google\\Google Talk\\googletalk.exe:*:Enabled:Google Talk"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:MSN Messenger 7.5"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:MSN Messenger 7.5"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
Remaining Files :
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes :
Wed 22 Sep 2004 221 A.SHR --- "C:\BOOT.BAK"
Wed 22 Sep 2004 204 A.SHR --- "C:\BOOTNXX.BAK"
Thu 6 Jan 2005 61,440 ...H. --- "C:\Program Files\MSN\msnupdate!@#@.exe"
Thu 6 Jan 2005 294,912 ...H. --- "C:\Program Files\MSN\txsrvc.dll"
Thu 6 Jan 2005 302,080 ...H. --- "C:\Program Files\MSN\unicows.dll"
Wed 1 Dec 2004 0 A.SH. --- "C:\WINDOWS\SMINST\HPCD.sys"
Thu 6 Nov 2008 108,223 ..SHR --- "C:\WINDOWS\system32\ckvo.exe"
Sun 11 Jan 2009 85,504 ..SHR --- "C:\WINDOWS\system32\ckvo0.dll"
Thu 10 Feb 2005 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Mon 8 Dec 2008 7,829,056 A..H. --- "C:\Program Files\Google\Picasa3\setup.exe"
Wed 11 Oct 2006 363 A..H. --- "C:\Program Files\InterActual\InterActual Player\iti8.tmp"
Wed 3 Jan 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp"
Mon 11 Jul 2005 38,400 ...H. --- "C:\Documents and Settings\Compaq_Administrator\Desktop\DEVORA\~WRL0001.tmp"
Sun 18 Dec 2005 37,376 ...H. --- "C:\Documents and Settings\Compaq_Administrator\Desktop\DEVORA\~WRL0014.tmp"
Mon 19 Dec 2005 41,472 ...H. --- "C:\Documents and Settings\Compaq_Administrator\Desktop\DEVORA\~WRL0057.tmp"
Thu 5 Jan 2006 60,416 ...H. --- "C:\Documents and Settings\Compaq_Administrator\Desktop\DEVORA\~WRL0183.tmp"
Mon 19 Dec 2005 40,960 ...H. --- "C:\Documents and Settings\Compaq_Administrator\Desktop\DEVORA\~WRL0190.tmp"
Mon 19 Dec 2005 40,960 ...H. --- "C:\Documents and Settings\Compaq_Administrator\Desktop\DEVORA\~WRL0777.tmp"
Mon 19 Dec 2005 39,424 ...H. --- "C:\Documents and Settings\Compaq_Administrator\Desktop\DEVORA\~WRL1217.tmp"
Mon 19 Dec 2005 40,448 ...H. --- "C:\Documents and Settings\Compaq_Administrator\Desktop\DEVORA\~WRL1253.tmp"
Sun 11 Feb 2007 36,864 ...H. --- "C:\Documents and Settings\Compaq_Administrator\Desktop\DEVORA\~WRL1417.tmp"
Sun 18 Dec 2005 37,888 ...H. --- "C:\Documents and Settings\Compaq_Administrator\Desktop\DEVORA\~WRL1452.tmp"
Mon 19 Dec 2005 40,448 ...H. --- "C:\Documents and Settings\Compaq_Administrator\Desktop\DEVORA\~WRL1569.tmp"
Wed 14 Feb 2007 35,328 ...H. --- "C:\Documents and Settings\Compaq_Administrator\Desktop\DEVORA\~WRL1679.tmp"
Mon 19 Dec 2005 40,448 ...H. --- "C:\Documents and Settings\Compaq_Administrator\Desktop\DEVORA\~WRL1846.tmp"
Mon 12 Feb 2007 37,888 ...H. --- "C:\Documents and Settings\Compaq_Administrator\Desktop\DEVORA\~WRL2071.tmp"
Wed 30 Mar 2005 47,616 ...H. --- "C:\Documents and Settings\Compaq_Administrator\Desktop\DEVORA\~WRL2288.tmp"
Mon 19 Dec 2005 39,936 ...H. --- "C:\Documents and Settings\Compaq_Administrator\Desktop\DEVORA\~WRL2495.tmp"
Mon 19 Dec 2005 39,936 ...H. --- "C:\Documents and Settings\Compaq_Administrator\Desktop\DEVORA\~WRL2825.tmp"
Sun 18 Dec 2005 36,352 ...H. --- "C:\Documents and Settings\Compaq_Administrator\Desktop\DEVORA\~WRL2842.tmp"
Mon 19 Dec 2005 39,424 ...H. --- "C:\Documents and Settings\Compaq_Administrator\Desktop\DEVORA\~WRL2928.tmp"
Sun 18 Dec 2005 36,864 ...H. --- "C:\Documents and Settings\Compaq_Administrator\Desktop\DEVORA\~WRL2990.tmp"
Sun 11 Feb 2007 36,352 ...H. --- "C:\Documents and Settings\Compaq_Administrator\Desktop\DEVORA\~WRL3088.tmp"
Sun 18 Dec 2005 38,400 ...H. --- "C:\Documents and Settings\Compaq_Administrator\Desktop\DEVORA\~WRL3327.tmp"
Sun 18 Dec 2005 37,888 ...H. --- "C:\Documents and Settings\Compaq_Administrator\Desktop\DEVORA\~WRL3444.tmp"
Sun 18 Dec 2005 36,864 ...H. --- "C:\Documents and Settings\Compaq_Administrator\Desktop\DEVORA\~WRL3561.tmp"
Sun 18 Dec 2005 38,400 ...H. --- "C:\Documents and Settings\Compaq_Administrator\Desktop\DEVORA\~WRL4076.tmp"
Sun 3 Apr 2005 7,798 A..H. --- "C:\Documents and Settings\Compaq_Administrator\Application Data\Microsoft\Office\Shortcut Bar\DesD0.tmp"
Thu 28 Jun 2007 15,478 A..H. --- "C:\Documents and Settings\Compaq_Administrator\Application Data\Microsoft\Office\Shortcut Bar\Fav6.tmp"
Sun 28 Sep 2008 12,118 A..H. --- "C:\Documents and Settings\Compaq_Administrator\Application Data\Microsoft\Office\Shortcut Bar\Off109.tmp"
Thu 28 Jun 2007 34,678 A..H. --- "C:\Documents and Settings\Compaq_Administrator\Application Data\Microsoft\Office\Shortcut Bar\Pro6.tmp"
Finished!