nevermind ignore all that. I just clicked 'ignore' instead of 'close'. I guess that did the trick. I got the log right here. By the way, if that was the last step in getting rid of the pop-ups, it didn't work. I'm still getting pummelled by pop-ups. For the lack of a better work, pummelled may be overexaggerating it. It more like mildly bothered. Anywho... without further adieu:
SDFix: Version 1.240
Run by Xing-Guo Sun MD on Thu 12/11/2008 at 10:01 PM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\Documents and Settings\Xing-Guo Sun MD\Desktop\SDFix\SDFix
Checking Services :
Restoring Default Security Values
Restoring Default Hosts File
Rebooting
Checking Files :
Trojan Files Found:
C:\WINDOWS\system32\TFTP6540 - Deleted
C:\WINDOWS\system32\TFTP6232 - Deleted
C:\WINDOWS\system32\TFTP9804 - Deleted
C:\WINDOWS\system32\TFTP15012 - Deleted
C:\WINDOWS\system32\TFTP1064 - Deleted
C:\WINDOWS\system32\TFTP2352 - Deleted
C:\WINDOWS\system32\TFTP2064 - Deleted
C:\WINDOWS\system32\TFTP1076 - Deleted
C:\WINDOWS\system32\TFTP2936 - Deleted
Removing Temp Files
ADS Check :
Final Check :
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-12-11 22:09:45
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\sharedaccess\parameters\firewallpolicy\standard prof
ile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\syste m32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\support.com\\client\\bin\\tgcmd.exe"="C:\\P rogram
Files\\support.com\\client\\bin\\tgcmd.exe:*

isab led:tgcmd Module"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program
Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\Messenger\\MSMSGS.EXE"="C:\\Program Files\\Messenger\\MSMSGS.EXE:*:Enabled:Windows
Messenger"
"D:\\sam's games\\NEXON\\MapleStory\\Patcher.exe"="D:\\sam's
games\\NEXON\\MapleStory\\Patcher.exe:*:Enabled:Pa tcher MFC ?? ????"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows
Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows
Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"D:\\Sam's stuff\\LimeWire\\LimeWire.exe"="D:\\Sam's stuff\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program
Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjou r"
"D:\\Sam's stuff\\iTunes.exe"="D:\\Sam's stuff\\iTunes.exe:*:Enabled:iTunes"
"D:\\sam's games\\Skype\\Phone\\Skype.exe"="D:\\sam's games\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\sharedaccess\parameters\firewallpolicy\domainpr ofil
e\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\syste m32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows
Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows
Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
Remaining Files :
File Backups: - C:\DOCUME~1\XING-G~1\Desktop\SDFix\SDFix\backups\backups.zip
Files with Hidden Attributes :
Thu 28 Feb 2002 0 ..SHR --- "C:\TEMP\EBD.SYS"
Fri 19 Jul 2002 53,248 ...HR --- "C:\WINDOWS\system32\DellSys.dll"
Fri 19 Jul 2002 17,153 ...HR --- "C:\WINDOWS\system32\drivers\omci.sys"
Wed 31 Jan 2007 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Fri 27 Jul 2007 1,040 A..H. --- "C:\Program Files\InterActual\InterActual Player\iti373.tmp"
Fri 19 Jul 2002 17,153 ...HR --- "C:\Program Files\Dell\DellSys\OMCI.SYS"
Wed 22 Dec 2004 76,568 ..SHR --- "C:\Program Files\Autodesk\Autodesk DWF Viewer\Setup.exe"
Thu 13 Jan 2005 11,360 A.SHR --- "C:\Program Files\Autodesk\Autodesk DWF Viewer\_Setupx.dll"
Thu 7 Aug 2008 1,024 A..H. --- "C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-
E849AAB0887F}\RP759\A0154399.sys"
Thu 11 Dec 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18
\2df9c5e1996f8d67585eb0c7918f9d33\BIT10.tmp"
Thu 11 Dec 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18
\913fb8692c662f7c4552b8d0a0e20b5f\BIT11.tmp"
Mon 12 Feb 2007 3,096,576 A..H. --- "C:\Documents and Settings\Xing-Guo Sun MD\Application Data\U3
\temp\Launchpad Removal.exe"
Thu 13 Mar 2008 7,318 A..H. --- "C:\Documents and Settings\Xing-Guo Sun MD\Application
Data\Microsoft\Office\Shortcut Bar\Off15.tmp"
Wed 14 Aug 2002 8,544 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\CATC USB Ethernet\Elndis.sys"
Wed 14 Aug 2002 33,149 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\CATC USB Ethernet\Usbd.sys"
Wed 14 Aug 2002 29,628 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\common\ASPICD.SYS"
Wed 14 Aug 2002 161,792 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\common\BOOTSRV.SYS"
Wed 14 Aug 2002 202,517 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\common\CMDS.EXE"
Wed 14 Aug 2002 22,158 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\common\COUNTRY.SYS"
Wed 14 Aug 2002 1,608 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\common\DEVICE.COM"
Wed 14 Aug 2002 15,345 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\common\DISPLAY.SYS"
Wed 14 Aug 2002 14,160 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\common\HIMEM.SYS"
Wed 14 Aug 2002 10,898 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\common\KEYB.COM"
Wed 14 Aug 2002 53,556 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\common\KEYBOARD.SYS"
Wed 14 Aug 2002 15,777 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\common\MODE.COM"
Wed 14 Aug 2002 37,681 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\common\MOUSE.COM"
Wed 14 Aug 2002 21,180 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\common\MSCDEX.EXE"
Wed 14 Aug 2002 8,513 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\common\NETBIND.COM"
Wed 14 Aug 2002 129,240 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\common\OHCI.EXE"
Wed 14 Aug 2002 28,439 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\common\Paralink.com"
Wed 14 Aug 2002 13,770 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\common\PROTMAN.EXE"
Wed 14 Aug 2002 130,980 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\common\UHCI.EXE"
Wed 14 Aug 2002 174,080 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\common\bootsrv16.sys"
Wed 14 Aug 2002 354,304 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\common\msbootsrv16.sy s"
Wed 14 Aug 2002 56,821 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\common\E.EXE"
Wed 14 Aug 2002 354,263 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\common\Net.exe"
Wed 14 Aug 2002 7,840 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\common\DLSHELP.SYS"
Wed 14 Aug 2002 374,038 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\common\CMDS16.EXE"
Wed 14 Aug 2002 49,242 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\common\ASPIOHCI.SYS"
Wed 14 Aug 2002 47,826 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\common\ASPI1394.SYS"
Wed 14 Aug 2002 32,396 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\common\GUEST.EXE"
Wed 14 Aug 2002 50,606 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\common\ASPIUHCI.SYS"
Wed 14 Aug 2002 35,340 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\common\ASPI2DOS.SYS"
Wed 14 Aug 2002 14,378 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\common\ASPI4DOS.SYS"
Wed 14 Aug 2002 37,984 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\common\ASPI8DOS.SYS"
Wed 14 Aug 2002 44,828 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\common\ASPI8U2.SYS"
Wed 14 Aug 2002 21,971 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\common\BTCDROM.SYS"
Wed 14 Aug 2002 30,955 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\common\BTDOSM.SYS"
Wed 14 Aug 2002 64,425 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\common\FLASHPT.SYS"
Wed 14 Aug 2002 41,302 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\common\OAKCDROM.SYS"
Wed 14 Aug 2002 17,043 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\DLink DE400 Packet\De400pd.com"
Wed 14 Aug 2002 11,491 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\DLink DMF560-TX Packet\Lmpd.com"
Wed 14 Aug 2002 17,791 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\DLink DT620 Packet\Dt620pd.com"
Wed 14 Aug 2002 11,786 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\IBM Crystal LAN Packet\Epktisa.com"
Wed 14 Aug 2002 18,300 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\Kingston EtheRx KNE110TX Packet\Ktc110p.com"
Wed 14 Aug 2002 13,360 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\Laneed LD-CDF Packet\Ldcdt.com"
Wed 14 Aug 2002 9,190 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\Laneed LD-PCI2TL Packet\Ldpcil.com"
Wed 14 Aug 2002 12,567 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\Melco LPC2-T\Lpchkat2.com"
Wed 14 Aug 2002 44,640 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\Planex FW-100TX Fast Ethernet Packet\FETPKT.COM"
Wed 14 Aug 2002 56,896 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\Planex FW-100TX Fast Ethernet Packet\Rtspkt.com"
Wed 14 Aug 2002 9,692 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\PXE Packet Driver\Undipd.com"
Wed 14 Aug 2002 32,484 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\WaveLAN Packet\Wvlan42.com"
Wed 14 Aug 2002 50,795 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\Xircom CBE10-100BTX\Cbendis.exe"
Wed 14 Aug 2002 48,223 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\Xircom CBE10-100BTX Packet\Cbepd.com"
Wed 14 Aug 2002 48,641 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\Xircom Ethernet II PS\Xpsndis.exe"
Wed 14 Aug 2002 49,015 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\Xircom Ethernet II PS Packet\Xpspd.com"
Wed 14 Aug 2002 33,860 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\Xircom PE3-10Bx\Pe3ndis.exe"
Wed 14 Aug 2002 50,405 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\Xircom RE10 - RE100 Packet\Ce3pd.com"
Wed 14 Aug 2002 48,491 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\Xircom RE10BT\Ce3ndis.exe"
Wed 14 Aug 2002 44,640 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\Planex FNW9x00T - ENW8300T Packet\fetpkt.com"
Wed 14 Aug 2002 52,225 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\Xircom Ethernet 10-100 + Modem\Cbendis.exe"
Wed 14 Aug 2002 50,175 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\Xircom Re-100Btx + Ce3B-100Btx\Ce3ndis.exe"
Wed 14 Aug 2002 12,732 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\3COM 3c509 Packet\3C5X9PD.COM"
Wed 14 Aug 2002 26,424 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\3COM 3c59x Packet\3C59XPD.COM"
Wed 14 Aug 2002 17,952 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\ACCTON EN1200 Packet\EC32PD.COM"
Wed 14 Aug 2002 29,499 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\ACCTON EN1203 Packet\PCIPD.COM"
Wed 14 Aug 2002 12,660 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\ACCTON EN1204 Packet\VLNWPD.COM"
Wed 14 Aug 2002 11,031 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\ACCTON EN1207 Packet\PCIPD.COM"
Wed 14 Aug 2002 10,710 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\ACCTON EN1207C Packet\PCIPD.COM"
Wed 14 Aug 2002 10,083 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\ACCTON EN1207D Packet\ACCPKT.COM"
Wed 14 Aug 2002 28,062 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\ACCTON EN1207F Packet\EN5251PD.COM"
Wed 14 Aug 2002 10,257 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\ACCTON EN1207TX Packet\PCIPD.COM"
Wed 14 Aug 2002 9,424 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\ACCTON EN1208 Packet\1208PD.COM"
Wed 14 Aug 2002 7,463 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\ACCTON EN1625 Packet\NEPD.COM"
Wed 14 Aug 2002 13,673 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\ACCTON EN1640 Packet\NWPD.COM"
Wed 14 Aug 2002 7,825 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\ACCTON EN1651 Packet\NWPD.COM"
Wed 14 Aug 2002 7,825 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\ACCTON EN1652 Packet\NWPD.COM"
Wed 14 Aug 2002 7,825 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\ACCTON EN1650 Packet\NWPD.COM"
Wed 14 Aug 2002 7,243 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\ACCTON EN1653 Packet\NE2PD.COM"
Wed 14 Aug 2002 7,825 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\ACCTON EN1656 Packet\NWPD.COM"
Wed 14 Aug 2002 14,438 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\ACCTON EN1657 Packet\NWPD.COM"
Wed 14 Aug 2002 14,438 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\ACCTON EN1658 Packet\NWPD.COM"
Wed 14 Aug 2002 7,825 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\ACCTON EN166X Packet\NWPD.COM"
Wed 14 Aug 2002 24,767 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\ACCTON EN2216 Packet\PCMPD.COM"
Wed 14 Aug 2002 25,460 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\ACCTON EN2218 Packet\PCMPD.COM"
Wed 14 Aug 2002 10,286 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\ACCTON EN2228 Packet\PCMPD.COM"
Wed 14 Aug 2002 28,866 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\ACCTON EN2320 Packet\EN5251PD.COM"
Wed 14 Aug 2002 11,854 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\DEC EtherWorks ISA (DE305) Packet\DE305.COM"
Wed 14 Aug 2002 62,391 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\DEC EtherWORKS DE500 Packet\DE500.COM"
Wed 14 Aug 2002 52,715 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\DEC EtherWORKS DE450 Packet\DE450.COM"
Wed 14 Aug 2002 48,224 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\Laneed LD 10-100AL Packet\L100al.com"
Wed 14 Aug 2002 9,537 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\SN 2000p Packet\PNPPD.COM"
Wed 14 Aug 2002 65,088 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\3COM 3c556 Packet\3C556.COM"
Wed 14 Aug 2002 53,786 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\common\pcdos\command. com"
Wed 14 Aug 2002 44,240 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\common\pcdos\IBMBIO.C OM"
Wed 14 Aug 2002 42,550 ...H. --- "C:\Documents and Settings\All Users\Application
Data\Symantec\Ghost\Template\common\pcdos\IBMDOS.C OM"
Finished!