oops sorry about that, here it is
SDFix: Version 1.182
Run by Compaq_Owner on Wed 05/14/2008 at 10:00 PM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\DOCUME~1\COMPAQ~1\Desktop\SDFix
Checking Services :
Name :
sysrest.sys
{DEF85C80-216A-43ab-AF70-1665EDBE2780}
Path :
\??\C:\WINDOWS\system32\sysrest.sys
\??\C:\WINDOWS\TEMP\44.tmp
sysrest.sys - Deleted
{DEF85C80-216A-43ab-AF70-1665EDBE2780} - Deleted
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Restoring Default Desktop Wallpaper
Rebooting
Checking Files :
Trojan Files Found:
C:\WINDOWS\SYSTEM32\9PHVU2.SYZ - Deleted
C:\WINDOWS\SYSTEM32\ASF936.SYZ - Deleted
C:\WINDOWS\SYSTEM32\D0WVH3.SYZ - Deleted
C:\WINDOWS\SYSTEM32\DNBCT8.SYZ - Deleted
C:\WINDOWS\SYSTEM32\LMMRNX.SYZ - Deleted
C:\WINDOWS\SYSTEM32\OWUNQJ.SYZ - Deleted
C:\WINDOWS\SYSTEM32\PGUCIN.SYZ - Deleted
C:\WINDOWS\SYSTEM32\SZJU7Y.SYZ - Deleted
C:\WINDOWS\SYSTEM32\U88A9F.SYZ - Deleted
C:\WINDOWS\SYSTEM32\UF4GVI.SYZ - Deleted
C:\WINDOWS\SYSTEM32\VBG6HI.SYZ - Deleted
C:\WINDOWS\SYSTEM32\ZD4HMP.SYZ - Deleted
C:\WINDOWS\SYSTEM32\CTFMONB.BMP - Deleted
C:\WINDOWS\SYSTEM32\TASKKILL.EXE - Deleted
C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\temCCC.tmp.exe - Deleted
C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\temCD0.tmp.exe - Deleted
C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\temCD4.tmp.exe - Deleted
C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\temD1D.tmp.exe - Deleted
C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\temD21.tmp.exe - Deleted
C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\temD25.tmp.exe - Deleted
C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\temD26.tmp.exe - Deleted
C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\updCD6.tmp.exe - Deleted
C:\Program Files\p2pnetworks\AlConfig.xml - Deleted
C:\Program Files\p2pnetworks\alp2plib.log - Deleted
C:\Program Files\p2pnetworks\alp2plib.log.bak - Deleted
C:\Program Files\p2pnetworks\install.log - Deleted
C:\Program Files\p2pnetworks\p2pnetworks.exe - Deleted
C:\Program Files\p2pnetworks\sp2p.cache - Deleted
C:\Program Files\p2pnetworks\uninst.exe - Deleted
C:\Program Files\p2pnetworks\bak\mpp2pl.exe - Deleted
C:\WINDOWS\b.exe - Deleted
C:\WINDOWS\system32\cssrss.exe - Deleted
C:\WINDOWS\system32\ctfmona.exe - Deleted
C:\WINDOWS\Temp\bca4e2da.$$$ - Deleted
C:\WINDOWS\Temp\fa56d7ec.$$$ - Deleted
C:\WINDOWS\system32\sysrest.sys - Deleted
Note - Files associated with the MBR Rootkit have been found on this system, to check the PC use Gmer or Dr.Web CureIt
Folder C:\Program Files\p2pnetworks - Removed
Removing Temp Files
ADS Check :
Final Check :
catchme 0.3.1359.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-05-14 22:15:39
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher]
"TracesProcessed"=dword:000000b2
"TracesSuccessful"=dword:00000070
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe

:enabled

xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe

:Enabled

xpsp3res.dll,-20000"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe

:Enabled:LimeWire"
"C:\\Program Files\\BitDownload\\BitDownload.exe"="C:\\Program Files\\BitDownload\\BitDownload.exe

:Enabled:Warez3"
"C:\\DOCUME~1\\COMPAQ~1\\LOCALS~1\\Temp\\DfEm.exe"="C:\\DOCUME~1\\COMPAQ~1\\LOCALS~1\\Temp\\DfEm.exe

:Enabled

HCP Client"
"C:\\DOCUME~1\\COMPAQ~1\\LOCALS~1\\Temp\\faui.exe"="C:\\DOCUME~1\\COMPAQ~1\\LOCALS~1\\Temp\\faui.exe

:Enabled

HCP Client"
"C:\\WINDOWS\\system32\\cssrss.exe"="C:\\WINDOWS\\system32\\cssrss.exe

:Enabled

HCP Client"
"C:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"="C:\\Program Files\\MySpace\\IM\\MySpaceIM.exe

:Enabled:MySpaceIM"
"C:\\Documents and Settings\\Compaq_Owner\\Local Settings\\Temp\\.tt8.tmp"="C:\\Documents and Settings\\Compaq_Owner\\Local Settings\\Temp\\.tt8.tmp

:Enabled:enable"
"C:\\WINDOWS\\system32\\sysrest32.exe"="C:\\WINDOWS\\system32\\sysrest32.exe

:Enabled:enable"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe

:enabled

xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe

:Enabled

xpsp3res.dll,-20000"
Remaining Files :
File Backups: - C:\DOCUME~1\COMPAQ~1\Desktop\SDFix\backups\backups.zip
Files with Hidden Attributes :
Wed 16 Nov 2005 213 A.SHR --- "C:\BOOT.BAK"
Wed 16 Nov 2005 196 A.SHR --- "C:\BOOTNXX.BAK"
Sat 15 Dec 2007 31 A..H. --- "C:\WINDOWS\uccspecc.sys"
Thu 11 Dec 2003 49,238 A..H. --- "C:\Program Files\America Online 9.0\aolphx.exe"
Thu 11 Dec 2003 36,954 A..H. --- "C:\Program Files\America Online 9.0\aoltray.exe"
Thu 11 Dec 2003 40,960 A..H. --- "C:\Program Files\America Online 9.0\RBM.exe"
Thu 11 Dec 2003 233,554 A..H. --- "C:\Program Files\America Online 9.0\waol.exe"
Thu 11 Dec 2003 49,238 A..H. --- "C:\Program Files\America Online 9.0b\aolphx.exe"
Thu 11 Dec 2003 36,954 A..H. --- "C:\Program Files\America Online 9.0b\aoltray.exe"
Thu 11 Dec 2003 40,960 A..H. --- "C:\Program Files\America Online 9.0b\RBM.exe"
Fri 23 Feb 2007 225,380 A..H. --- "C:\Program Files\America Online 9.0b\waol.exe"
Thu 11 Dec 2003 49,238 A..H. --- "C:\Program Files\America Online 9.0c\aolphx.exe"
Thu 11 Dec 2003 36,954 A..H. --- "C:\Program Files\America Online 9.0c\aoltray.exe"
Thu 11 Dec 2003 40,960 A..H. --- "C:\Program Files\America Online 9.0c\RBM.exe"
Fri 23 Feb 2007 225,380 A..H. --- "C:\Program Files\America Online 9.0c\waol.exe"
Thu 1 Feb 2007 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Wed 14 May 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\c3e13424b5ca403dd00c8550d4b5fddd\BITF.tmp"
Thu 11 Dec 2003 111,824 A..H. --- "C:\Program Files\Common Files\aolshare\shell\us\shellext.dll"
Finished!