kerzhong
2008-02-19, 04:00
I have read some of the earlier posts helping to remove these files, but I am having trouble installing icesword.exe. Computer says that it is not a valid win32 application and then freezes. Other than that, this virus seems to have deleted folders on my main (C) drive (although the corresponding disk space is not cleared) and my second (D) drive now shows up as unformatted. Tried to restore the system (running XP) but the function did not work.
Here are the results from:
Deckard's System Scanner v20071014.68
Run by Ker Zhong on 2008-02-18 17:53:09
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 2 Restore Point(s) --
2: 2008-02-19 01:53:14 UTC - RP2 - Deckard's System Scanner Restore Point
1: 2008-02-19 01:33:08 UTC - RP1 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
System Drive C: has 15.59 GiB (less than 15%) free.
-- HijackThis Clone ------------------------------------------------------------
Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2008-02-18 17:54:58
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (7.00.6000.16608)
Boot mode: Normal
Running processes:
C:\WINDOWS\SYSTEM32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\SYSTEM32\services.exe
C:\WINDOWS\SYSTEM32\lsass.exe
C:\WINDOWS\SYSTEM32\svchost.exe
C:\WINDOWS\SYSTEM32\svchost.exe
C:\WINDOWS\SYSTEM32\svchost.exe
C:\WINDOWS\SYSTEM32\spoolsv.exe
C:\WINDOWS\SYSTEM32\CTSVCCDA.EXE
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\Samsung\ComSMMgr\SSMMgr.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\WINDOWS\SYSTEM32\ctfmon.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\Program Files\WordWeb\wweb32.exe
C:\Program Files\Symantec AntiVirus\VPC32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\SYSTEM32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Ker Zhong\My Documents\dss.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\printray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Samsung Common SM] "C:\WINDOWS\Samsung\ComSMMgr\ssmmgr.exe" /autorun
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [sealmon] C:\Program Files\SealedMedia\sealmon.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime (User 'Default user')
O4 - Startup: GBPVRTray.exe.lnk = ?
O4 - Startup: WordWeb.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &WordWeb... - res://C:\WINDOWS\wweb32.dll/lookup.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00000075-9980-0010-8000-00AA00389B71} () - http://codecs.microsoft.com/codecs/i386/voxacm.CAB
O16 - DPF: {01111F00-3E00-11D2-8470-0060089874ED} () - http://supportsoft.adelphia.net/sdccommon/download/tgctlins.cab
O16 - DPF: {33564D57-9980-0010-8000-00AA00389B71} () - http://codecs.microsoft.com/codecs/i386/wmv9dmo.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} () - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38094.5093402778
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://xpphoto.lifepics.com/net/Uploader/ImageUploader3.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {DADE1C2F-5A48-445C-82B5-3A5F102E84DF} (LifePicsUploader.UserControl1) - http://xpphoto.lifepics.com/common/UserUpload/LifePicsUploader.CAB
O18 - Protocol: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL
O18 - Protocol: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL
O18 - Protocol: mso-offdap - {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\SYSTEM32\ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\SYSTEM32\CTSVCCDA.EXE
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: GB-PVR Recording Service - devnz.com - C:\Program Files\devnz\gbpvr\GBPVRRecordingService.exe
O23 - Service: LexBce Server (LexBceS) - Unknown owner - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_1.EXE
O23 - Service: Lexar JD31 (LxrJD31s) - Unknown owner - LxrJD31s.exe
O23 - Service: MSSQLServerADHelper - Unknown owner - C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\SYSTEM32\nvsvc32.exe
O23 - Service: SavRoam - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
--
End of file - 8632 bytes
-- File Associations -----------------------------------------------------------
.bat - batfile - DefaultIcon - C:\WINDOWS\SYSTEM32\SHELL32.DLL,-153
.com - comfile - DefaultIcon - C:\WINDOWS\SYSTEM32\SHELL32.DLL,2
.hlp - hlpfile - DefaultIcon - C:\WINDOWS\SYSTEM32\SHELL32.DLL,23
.ini - inifile - DefaultIcon - shell32.dll,-151
.reg - regfile - DefaultIcon - C:\WINDOWS\regedit.exe,1
.txt - txtfile - DefaultIcon - shell32.dll,-152
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R1 srosa (Megadrv3) - c:\windows\system32\drivers\srosa.sys
R2 DgiVecp (Team MFP Comm Driver) - c:\windows\system32\drivers\dgivecp.sys <Not Verified; DeviceGuys, Inc.; DeviceGuys, Inc. Team MFP for Windows NT, 9x, and 3.1>
R2 LxrJD31d - c:\windows\system32\drivers\lxrjd31d.sys
R3 ASAPIW2k - c:\windows\system32\drivers\asapiw2k.sys <Not Verified; Pinnacle Systems GmbH; asapi>
R3 Pcouffin (Low level access layer for CD devices) - c:\windows\system32\drivers\pcouffin.sys <Not Verified; VSO Software; Patin couffin engine>
R3 pfc (Padus ASPI Shell) - c:\windows\system32\drivers\pfc.sys <Not Verified; Padus, Inc.; Padus(R) ASPI Shell>
S3 atinevxx (ATI WDM Rage Theater Video NSP) - c:\windows\system32\drivers\atinevxx.sys <Not Verified; ATI Technologies Inc.; ATI WDM RT>
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
S2 GB-PVR Recording Service - "c:\program files\devnz\gbpvr\gbpvrrecordingservice.exe" <Not Verified; devnz.com; GB-PVR Recording Service>
S2 LexBceS (LexBce Server) - c:\windows\system32\lexbces.exe (file missing)
S2 LxrJD31s (Lexar JD31) - lxrjd31s.exe (file missing)
S2 Symantec AntiVirus - "c:\program files\symantec antivirus\rtvscan.exe" <Not Verified; Symantec Corporation; Symantec AntiVirus>
S3 MSSQLServerADHelper - c:\program files\microsoft sql server\80\tools\binn\sqladhlp.exe (file missing)
-- Device Manager: Disabled ----------------------------------------------------
Class GUID: {4D36E97D-E325-11CE-BFC1-08002BE10318}
Description: PCI standard RAM Controller
Device ID: PCI\VEN_10DE&DEV_01EE&SUBSYS_0C1710DE&REV_C1\3&13C0B0C5&0&02
Manufacturer: (Standard system devices)
Name: PCI standard RAM Controller
PNP Device ID: PCI\VEN_10DE&DEV_01EE&SUBSYS_0C1710DE&REV_C1\3&13C0B0C5&0&02
Service:
Class GUID: {4D36E97D-E325-11CE-BFC1-08002BE10318}
Description: PCI standard RAM Controller
Device ID: PCI\VEN_10DE&DEV_01ED&SUBSYS_0C1710DE&REV_C1\3&13C0B0C5&0&03
Manufacturer: (Standard system devices)
Name: PCI standard RAM Controller
PNP Device ID: PCI\VEN_10DE&DEV_01ED&SUBSYS_0C1710DE&REV_C1\3&13C0B0C5&0&03
Service:
Class GUID: {4D36E97D-E325-11CE-BFC1-08002BE10318}
Description: PCI standard RAM Controller
Device ID: PCI\VEN_10DE&DEV_01EC&SUBSYS_0C1710DE&REV_C1\3&13C0B0C5&0&04
Manufacturer: (Standard system devices)
Name: PCI standard RAM Controller
PNP Device ID: PCI\VEN_10DE&DEV_01EC&SUBSYS_0C1710DE&REV_C1\3&13C0B0C5&0&04
Service:
Class GUID: {4D36E97D-E325-11CE-BFC1-08002BE10318}
Description: PCI standard RAM Controller
Device ID: PCI\VEN_10DE&DEV_01EF&SUBSYS_0C1710DE&REV_C1\3&13C0B0C5&0&05
Manufacturer: (Standard system devices)
Name: PCI standard RAM Controller
PNP Device ID: PCI\VEN_10DE&DEV_01EF&SUBSYS_0C1710DE&REV_C1\3&13C0B0C5&0&05
Service:
Class GUID: {4D36E97D-E325-11CE-BFC1-08002BE10318}
Description: SM Bus Controller
Device ID: PCI\VEN_10DE&DEV_0064&SUBSYS_1C02147B&REV_A2\3&13C0B0C5&0&09
Manufacturer:
Name: SM Bus Controller
PNP Device ID: PCI\VEN_10DE&DEV_0064&SUBSYS_1C02147B&REV_A2\3&13C0B0C5&0&09
Service:
Class GUID:
Description:
Device ID: DISPLAY\NTATIVRV01\5&2276798C&0&80000008&02&00
Manufacturer:
Name:
PNP Device ID: DISPLAY\NTATIVRV01\5&2276798C&0&80000008&02&00
Service:
-- Scheduled Tasks -------------------------------------------------------------
2008-02-18 17:44:00 258 --a------ C:\WINDOWS\Tasks\Uninstall Expiration Reminder.job
2008-02-18 05:58:22 482 --a------ C:\WINDOWS\Tasks\ShowShifter Regular ShowGuide Update.job
2008-02-06 23:00:00 502 --a------ C:\WINDOWS\Tasks\Tune-up Application Start.job
-- Files created between 2008-01-18 and 2008-02-18 -----------------------------
2008-02-18 16:36:09 81288 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2008-02-18 16:36:02 0 d-------- C:\Program Files\Spyware Doctor
2008-02-18 16:36:02 0 d-------- C:\Documents and Settings\Ker Zhong\Application Data\PC Tools
2008-02-18 14:55:07 71172 --a------ C:\WINDOWS\system32\mdelk.exe
2008-02-18 14:42:44 888832 --a------ C:\WINDOWS\system32\securenet.dll
2008-02-16 03:07:01 0 --a------ C:\WINDOWS\ativpsrm.bin
2008-02-12 16:19:55 0 d-------- C:\Documents and Settings\All Users\Application Data\Adobe
-- Find3M Report ---------------------------------------------------------------
2008-02-18 16:57:37 0 d-------- C:\Program Files\Bug Doctor
2008-02-18 16:04:32 0 d-------- C:\Program Files\PeerGuardian2
2008-02-18 14:51:24 0 d-------- C:\Program Files\eMule
2008-02-16 03:08:03 0 d-------- C:\Program Files\Symantec AntiVirus
2008-02-12 16:20:23 0 d-------- C:\Documents and Settings\Ker Zhong\Application Data\AdobeUM
2008-02-12 10:42:52 0 d-------- C:\Documents and Settings\Ker Zhong\Application Data\Adobe
2008-02-08 14:30:25 0 d-------- C:\Documents and Settings\Ker Zhong\Application Data\FrostWire
2008-01-03 19:14:54 0 d-------- C:\Program Files\OverDrive Media Console
2008-01-02 15:29:33 0 d-------- C:\Documents and Settings\Ker Zhong\Application Data\OverDrive
2007-12-31 09:48:48 0 d-------- C:\Program Files\FrostWire
2007-12-31 09:48:38 0 d-------- C:\Program Files\LimeWire
2007-12-30 19:17:57 0 d-------- C:\Program Files\Common Files\Symantec Shared
2007-12-30 19:15:24 0 d-------- C:\Program Files\Folder Scout Labs
2007-12-30 18:32:51 0 d-------- C:\Program Files\Messenger
2007-12-30 18:15:18 0 d-------- C:\Program Files\QuickTime
2007-12-30 18:10:07 0 --------- C:\WINDOWS\system32\mljgfcc.dll
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [07/15/2004 10:42 AM]
"nwiz"="nwiz.exe" [07/15/2004 10:42 AM C:\WINDOWS\SYSTEM32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [07/15/2004 10:42 AM]
"PrinTray"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\printray.exe" [05/10/2000 08:55 AM]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [07/09/2001 01:50 AM]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [09/24/2004 02:44 PM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [09/25/2007 12:11 AM]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [05/16/2005 10:05 AM]
"Samsung Common SM"="C:\WINDOWS\Samsung\ComSMMgr\ssmmgr.exe" [03/13/2005 09:01 PM]
"PinnacleDriverCheck"="C:\WINDOWS\system32\PSDrvCheck.exe" [12/04/2003 11:34 AM]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [11/30/2004 08:10 PM]
"@"="" []
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [11/30/2004 11:25 PM]
"RegistryMechanic"="" []
"sealmon"="C:\Program Files\SealedMedia\sealmon.exe" []
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [02/18/2008 05:49 PM]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [02/18/2008 04:59 PM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/03/2004 11:56 PM]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"<NO NAME>"=
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
Here are the results from:
Deckard's System Scanner v20071014.68
Run by Ker Zhong on 2008-02-18 17:53:09
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 2 Restore Point(s) --
2: 2008-02-19 01:53:14 UTC - RP2 - Deckard's System Scanner Restore Point
1: 2008-02-19 01:33:08 UTC - RP1 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
System Drive C: has 15.59 GiB (less than 15%) free.
-- HijackThis Clone ------------------------------------------------------------
Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2008-02-18 17:54:58
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (7.00.6000.16608)
Boot mode: Normal
Running processes:
C:\WINDOWS\SYSTEM32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\SYSTEM32\services.exe
C:\WINDOWS\SYSTEM32\lsass.exe
C:\WINDOWS\SYSTEM32\svchost.exe
C:\WINDOWS\SYSTEM32\svchost.exe
C:\WINDOWS\SYSTEM32\svchost.exe
C:\WINDOWS\SYSTEM32\spoolsv.exe
C:\WINDOWS\SYSTEM32\CTSVCCDA.EXE
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\Samsung\ComSMMgr\SSMMgr.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\WINDOWS\SYSTEM32\ctfmon.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\Program Files\WordWeb\wweb32.exe
C:\Program Files\Symantec AntiVirus\VPC32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\SYSTEM32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Ker Zhong\My Documents\dss.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\printray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Samsung Common SM] "C:\WINDOWS\Samsung\ComSMMgr\ssmmgr.exe" /autorun
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [sealmon] C:\Program Files\SealedMedia\sealmon.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime (User 'Default user')
O4 - Startup: GBPVRTray.exe.lnk = ?
O4 - Startup: WordWeb.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &WordWeb... - res://C:\WINDOWS\wweb32.dll/lookup.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00000075-9980-0010-8000-00AA00389B71} () - http://codecs.microsoft.com/codecs/i386/voxacm.CAB
O16 - DPF: {01111F00-3E00-11D2-8470-0060089874ED} () - http://supportsoft.adelphia.net/sdccommon/download/tgctlins.cab
O16 - DPF: {33564D57-9980-0010-8000-00AA00389B71} () - http://codecs.microsoft.com/codecs/i386/wmv9dmo.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} () - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38094.5093402778
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://xpphoto.lifepics.com/net/Uploader/ImageUploader3.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {DADE1C2F-5A48-445C-82B5-3A5F102E84DF} (LifePicsUploader.UserControl1) - http://xpphoto.lifepics.com/common/UserUpload/LifePicsUploader.CAB
O18 - Protocol: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL
O18 - Protocol: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL
O18 - Protocol: mso-offdap - {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\SYSTEM32\ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\SYSTEM32\CTSVCCDA.EXE
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: GB-PVR Recording Service - devnz.com - C:\Program Files\devnz\gbpvr\GBPVRRecordingService.exe
O23 - Service: LexBce Server (LexBceS) - Unknown owner - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_1.EXE
O23 - Service: Lexar JD31 (LxrJD31s) - Unknown owner - LxrJD31s.exe
O23 - Service: MSSQLServerADHelper - Unknown owner - C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\SYSTEM32\nvsvc32.exe
O23 - Service: SavRoam - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
--
End of file - 8632 bytes
-- File Associations -----------------------------------------------------------
.bat - batfile - DefaultIcon - C:\WINDOWS\SYSTEM32\SHELL32.DLL,-153
.com - comfile - DefaultIcon - C:\WINDOWS\SYSTEM32\SHELL32.DLL,2
.hlp - hlpfile - DefaultIcon - C:\WINDOWS\SYSTEM32\SHELL32.DLL,23
.ini - inifile - DefaultIcon - shell32.dll,-151
.reg - regfile - DefaultIcon - C:\WINDOWS\regedit.exe,1
.txt - txtfile - DefaultIcon - shell32.dll,-152
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R1 srosa (Megadrv3) - c:\windows\system32\drivers\srosa.sys
R2 DgiVecp (Team MFP Comm Driver) - c:\windows\system32\drivers\dgivecp.sys <Not Verified; DeviceGuys, Inc.; DeviceGuys, Inc. Team MFP for Windows NT, 9x, and 3.1>
R2 LxrJD31d - c:\windows\system32\drivers\lxrjd31d.sys
R3 ASAPIW2k - c:\windows\system32\drivers\asapiw2k.sys <Not Verified; Pinnacle Systems GmbH; asapi>
R3 Pcouffin (Low level access layer for CD devices) - c:\windows\system32\drivers\pcouffin.sys <Not Verified; VSO Software; Patin couffin engine>
R3 pfc (Padus ASPI Shell) - c:\windows\system32\drivers\pfc.sys <Not Verified; Padus, Inc.; Padus(R) ASPI Shell>
S3 atinevxx (ATI WDM Rage Theater Video NSP) - c:\windows\system32\drivers\atinevxx.sys <Not Verified; ATI Technologies Inc.; ATI WDM RT>
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
S2 GB-PVR Recording Service - "c:\program files\devnz\gbpvr\gbpvrrecordingservice.exe" <Not Verified; devnz.com; GB-PVR Recording Service>
S2 LexBceS (LexBce Server) - c:\windows\system32\lexbces.exe (file missing)
S2 LxrJD31s (Lexar JD31) - lxrjd31s.exe (file missing)
S2 Symantec AntiVirus - "c:\program files\symantec antivirus\rtvscan.exe" <Not Verified; Symantec Corporation; Symantec AntiVirus>
S3 MSSQLServerADHelper - c:\program files\microsoft sql server\80\tools\binn\sqladhlp.exe (file missing)
-- Device Manager: Disabled ----------------------------------------------------
Class GUID: {4D36E97D-E325-11CE-BFC1-08002BE10318}
Description: PCI standard RAM Controller
Device ID: PCI\VEN_10DE&DEV_01EE&SUBSYS_0C1710DE&REV_C1\3&13C0B0C5&0&02
Manufacturer: (Standard system devices)
Name: PCI standard RAM Controller
PNP Device ID: PCI\VEN_10DE&DEV_01EE&SUBSYS_0C1710DE&REV_C1\3&13C0B0C5&0&02
Service:
Class GUID: {4D36E97D-E325-11CE-BFC1-08002BE10318}
Description: PCI standard RAM Controller
Device ID: PCI\VEN_10DE&DEV_01ED&SUBSYS_0C1710DE&REV_C1\3&13C0B0C5&0&03
Manufacturer: (Standard system devices)
Name: PCI standard RAM Controller
PNP Device ID: PCI\VEN_10DE&DEV_01ED&SUBSYS_0C1710DE&REV_C1\3&13C0B0C5&0&03
Service:
Class GUID: {4D36E97D-E325-11CE-BFC1-08002BE10318}
Description: PCI standard RAM Controller
Device ID: PCI\VEN_10DE&DEV_01EC&SUBSYS_0C1710DE&REV_C1\3&13C0B0C5&0&04
Manufacturer: (Standard system devices)
Name: PCI standard RAM Controller
PNP Device ID: PCI\VEN_10DE&DEV_01EC&SUBSYS_0C1710DE&REV_C1\3&13C0B0C5&0&04
Service:
Class GUID: {4D36E97D-E325-11CE-BFC1-08002BE10318}
Description: PCI standard RAM Controller
Device ID: PCI\VEN_10DE&DEV_01EF&SUBSYS_0C1710DE&REV_C1\3&13C0B0C5&0&05
Manufacturer: (Standard system devices)
Name: PCI standard RAM Controller
PNP Device ID: PCI\VEN_10DE&DEV_01EF&SUBSYS_0C1710DE&REV_C1\3&13C0B0C5&0&05
Service:
Class GUID: {4D36E97D-E325-11CE-BFC1-08002BE10318}
Description: SM Bus Controller
Device ID: PCI\VEN_10DE&DEV_0064&SUBSYS_1C02147B&REV_A2\3&13C0B0C5&0&09
Manufacturer:
Name: SM Bus Controller
PNP Device ID: PCI\VEN_10DE&DEV_0064&SUBSYS_1C02147B&REV_A2\3&13C0B0C5&0&09
Service:
Class GUID:
Description:
Device ID: DISPLAY\NTATIVRV01\5&2276798C&0&80000008&02&00
Manufacturer:
Name:
PNP Device ID: DISPLAY\NTATIVRV01\5&2276798C&0&80000008&02&00
Service:
-- Scheduled Tasks -------------------------------------------------------------
2008-02-18 17:44:00 258 --a------ C:\WINDOWS\Tasks\Uninstall Expiration Reminder.job
2008-02-18 05:58:22 482 --a------ C:\WINDOWS\Tasks\ShowShifter Regular ShowGuide Update.job
2008-02-06 23:00:00 502 --a------ C:\WINDOWS\Tasks\Tune-up Application Start.job
-- Files created between 2008-01-18 and 2008-02-18 -----------------------------
2008-02-18 16:36:09 81288 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2008-02-18 16:36:02 0 d-------- C:\Program Files\Spyware Doctor
2008-02-18 16:36:02 0 d-------- C:\Documents and Settings\Ker Zhong\Application Data\PC Tools
2008-02-18 14:55:07 71172 --a------ C:\WINDOWS\system32\mdelk.exe
2008-02-18 14:42:44 888832 --a------ C:\WINDOWS\system32\securenet.dll
2008-02-16 03:07:01 0 --a------ C:\WINDOWS\ativpsrm.bin
2008-02-12 16:19:55 0 d-------- C:\Documents and Settings\All Users\Application Data\Adobe
-- Find3M Report ---------------------------------------------------------------
2008-02-18 16:57:37 0 d-------- C:\Program Files\Bug Doctor
2008-02-18 16:04:32 0 d-------- C:\Program Files\PeerGuardian2
2008-02-18 14:51:24 0 d-------- C:\Program Files\eMule
2008-02-16 03:08:03 0 d-------- C:\Program Files\Symantec AntiVirus
2008-02-12 16:20:23 0 d-------- C:\Documents and Settings\Ker Zhong\Application Data\AdobeUM
2008-02-12 10:42:52 0 d-------- C:\Documents and Settings\Ker Zhong\Application Data\Adobe
2008-02-08 14:30:25 0 d-------- C:\Documents and Settings\Ker Zhong\Application Data\FrostWire
2008-01-03 19:14:54 0 d-------- C:\Program Files\OverDrive Media Console
2008-01-02 15:29:33 0 d-------- C:\Documents and Settings\Ker Zhong\Application Data\OverDrive
2007-12-31 09:48:48 0 d-------- C:\Program Files\FrostWire
2007-12-31 09:48:38 0 d-------- C:\Program Files\LimeWire
2007-12-30 19:17:57 0 d-------- C:\Program Files\Common Files\Symantec Shared
2007-12-30 19:15:24 0 d-------- C:\Program Files\Folder Scout Labs
2007-12-30 18:32:51 0 d-------- C:\Program Files\Messenger
2007-12-30 18:15:18 0 d-------- C:\Program Files\QuickTime
2007-12-30 18:10:07 0 --------- C:\WINDOWS\system32\mljgfcc.dll
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [07/15/2004 10:42 AM]
"nwiz"="nwiz.exe" [07/15/2004 10:42 AM C:\WINDOWS\SYSTEM32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [07/15/2004 10:42 AM]
"PrinTray"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\printray.exe" [05/10/2000 08:55 AM]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [07/09/2001 01:50 AM]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [09/24/2004 02:44 PM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [09/25/2007 12:11 AM]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [05/16/2005 10:05 AM]
"Samsung Common SM"="C:\WINDOWS\Samsung\ComSMMgr\ssmmgr.exe" [03/13/2005 09:01 PM]
"PinnacleDriverCheck"="C:\WINDOWS\system32\PSDrvCheck.exe" [12/04/2003 11:34 AM]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [11/30/2004 08:10 PM]
"@"="" []
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [11/30/2004 11:25 PM]
"RegistryMechanic"="" []
"sealmon"="C:\Program Files\SealedMedia\sealmon.exe" []
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [02/18/2008 05:49 PM]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [02/18/2008 04:59 PM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/03/2004 11:56 PM]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"<NO NAME>"=
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime