ComboFix log
Hi-
Here's the ComboFix log...HJT log to follow in a few minutes. Thanks, George
ComboFix 08-05-29.1 - NYP 2008-05-31 23:04:39.1 - NTFSx86
Running from: C:\Documents and Settings\NYP\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\NYP\My Documents\STEM32~1
C:\Documents and Settings\NYP\My Documents\YSTEM~1
C:\Documents and Settings\NYP\Start Menu\Programs\Internet Speed Monitor
C:\Documents and Settings\NYP\Start Menu\Programs\Internet Speed Monitor\Check Now.lnk
C:\Documents and Settings\NYP\Start Menu\Programs\Internet Speed Monitor\Uninstall.lnk
C:\Program Files\Common Files\wnsxs~1
C:\Program Files\Common Files\wnsxs~1\?explore.exe
C:\Program Files\Common Files\ystem3~1
C:\Program Files\Common Files\ystem3~1\?ystem32\
C:\Program Files\Common Files\ystem3~1\dvdplay.exe
C:\Program Files\ISM
C:\Program Files\ISM\ism.exe
C:\Program Files\ISM\Uninstall.exe
C:\Program Files\outerinfo
C:\Program Files\outerinfo\FF\chrome.manifest
C:\Program Files\outerinfo\FF\components\FF.dll
C:\Program Files\outerinfo\FF\components\OuterinfoAds.xpt
C:\Program Files\outerinfo\FF\install.rdf
C:\Program Files\outerinfo\OiUninstaller.exe
C:\Program Files\outerinfo\outerinfo.ico
C:\Program Files\QdrDrive
C:\Program Files\QdrDrive\qdrloader.exe
C:\Program Files\QdrModule
C:\Program Files\QdrModule\dicer.gz
C:\Program Files\QdrModule\dicy.gz
C:\Program Files\QdrModule\kwdy.gz
C:\Program Files\QdrModule\mainladupd.exe
C:\Program Files\QdrModule\pckr.dat
C:\Program Files\QdrModule\QdrModule16.exe
C:\Program Files\QdrModule\QdrModule17.exe
C:\Program Files\QdrPack
C:\Program Files\QdrPack\dicts.gz
C:\Program Files\QdrPack\dictys.gz
C:\Program Files\QdrPack\QdrPack15.exe
C:\Program Files\QdrPack\QdrPack16.exe
C:\Program Files\QdrPack\trgts.gz
C:\Program Files\RcvSystem
C:\Program Files\RcvSystem\httpdchk.dll
C:\Program Files\Spcron
C:\Program Files\Spcron\Spcron.dll
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\temp\tn3
C:\WINDOWS\BM5bb47f8a.xml
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\b1
C:\WINDOWS\system32\DJiOrtwa.ini
C:\WINDOWS\system32\DJiOrtwa.ini2
C:\WINDOWS\system32\drivers\rawwann.sys
C:\WINDOWS\system32\dsigyqlk.ini
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\msnav32.ax
C:\WINDOWS\system32\n3
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\RrtuBcfe.ini
C:\WINDOWS\system32\RrtuBcfe.ini2
C:\WINDOWS\system32\rwwnw64d.exe
C:\WINDOWS\system32\VuxEgfii.ini
C:\WINDOWS\system32\VuxEgfii.ini2
C:\WINDOWS\system32\x4
C:\WINDOWS\system32\x4\demw136.exe
C:\WINDOWS\system32\xzej.dll
C:\WINDOWS\system32\zxdnt3d.cfg
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_RAWWANN
-------\Service_rawwann
((((((((((((((((((((((((( Files Created from 2008-05-01 to 2008-06-01 )))))))))))))))))))))))))))))))
.
2008-05-31 23:13 . 2008-05-31 23:13 21 --a------ C:\WINDOWS\system32\zxdnt3d.cfg
2008-05-30 01:46 . 2008-05-30 01:46 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-30 01:34 . 2008-05-30 01:34 49,162 --a------ C:\WINDOWS\system32\jqwnw64j.exe
2008-05-30 01:01 . 2008-05-30 01:04 63,918 --a------ C:\WINDOWS\system32\{35a6ae75-c06a-1fc9-e65b-9ee1f3540a3c}.dll-uninst.exe
2008-05-30 01:00 . 2008-05-30 01:01 401,976 --a------ C:\WINDOWS\system32\g29.exe
2008-05-30 00:42 . 2008-05-30 00:42 13,942 --a------ C:\WINDOWS\system32\iphone-011.ico
2008-05-30 00:11 . 2008-05-30 00:11 4,286 --a------ C:\WINDOWS\system32\Jamster.ico
2008-05-29 20:59 . 2008-05-29 21:00 200,779 --a------ C:\WINDOWS\system32\rcntrkdm.exe
2008-05-29 20:59 . 2008-05-29 20:59 88,961 --a------ C:\WINDOWS\system32\mysidesearch_sidebar_uninstall.exe
2008-05-29 20:58 . 2008-05-29 20:59 298,308 --a------ C:\WINDOWS\system32\gside.exe
2008-05-28 23:28 . 2008-05-28 23:28 9,662 --a------ C:\WINDOWS\system32\pinkip.ico
2008-05-28 20:22 . 2008-05-28 20:22 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-05-28 20:22 . 2008-05-28 20:22 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-05-27 22:25 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-05-27 22:25 . 2006-04-27 17:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-05-27 22:25 . 2008-05-27 13:54 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
2008-05-27 22:25 . 2008-05-18 21:40 82,944 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-05-27 22:25 . 2008-05-18 21:40 82,944 --a------ C:\WINDOWS\system32\404Fix.exe
2008-05-27 22:25 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-05-27 22:25 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-05-27 22:25 . 2007-10-04 00:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-05-27 21:48 . 2008-05-27 21:48 167,976 --a------ C:\WINDOWS\system32\drivers\core.cache.dsk
2008-05-27 19:53 . 2008-05-27 21:32 6,044 --a------ C:\WINDOWS\system32\tmp.reg
2008-05-27 19:43 . 2008-05-27 19:43 200,767 --a------ C:\WINDOWS\system32\tcntaxdn.exe
2008-05-27 19:43 . 2008-05-27 19:43 862 --a------ C:\WINDOWS\system32\winpfz33.sys
2008-05-27 09:34 . 2008-05-27 09:34 370,688 --a------ C:\WINDOWS\system32\{35a6ae75-c06a-1fc9-e65b-9ee1f3540a3c}.dll
2008-05-25 17:14 . 2008-05-31 22:40 2,184 --a------ C:\WINDOWS\system32\wpa.dbl
2008-05-24 09:14 . 2008-05-31 22:43 54,202 --a------ C:\VETlog.dmp
2008-05-11 00:11 . 2008-05-11 00:11 9,662 --a------ C:\WINDOWS\system32\ZoneAlarmIconUS.ico
2008-05-02 10:22 . 2008-05-02 10:22 <DIR> d-------- C:\WINDOWS\rffi
2008-05-02 10:22 . 2008-05-02 15:21 <DIR> d-------- C:\Program Files\Common Files\rffi
2008-05-02 10:12 . 2008-05-02 10:12 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-05-02 10:12 . 2008-05-02 10:23 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-02 10:08 . 2008-05-02 10:08 <DIR> d-------- C:\Program Files\Lavasoft
2008-05-02 10:08 . 2008-05-02 10:11 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-05-02 10:07 . 2008-05-02 10:07 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-05-01 08:40 . 2008-05-01 05:40 68,608 --------- C:\WINDOWS\b155.exe_old
2008-05-01 08:00 . 2008-05-01 05:00 273,408 --------- C:\WINDOWS\b148.exe_old
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{25340342-330E-4395-A8B4-5CE97F6BC0D8}]
C:\WINDOWS\system32\efcButrR.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{56AAAD03-1EF9-4B07-8196-12F1C125F7AD}]
C:\WINDOWS\system32\awtrOiJD.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7605204a-1bf2-6b53-2777-53f8a87e9669}]
C:\WINDOWS\system32\{81f3a1e4-cd23-1d59-1798-24c78d1a1745}.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9506910A-0F94-4ea1-B567-7070428B8B2B}]
2008-03-27 11:35 333824 --a------ C:\WINDOWS\system32\mysidesearch_sidebar.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DF71DBA4-D312-448B-85AD-B0D5F85D16BD}]
C:\WINDOWS\system32\iifgExuV.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{fdd7b81d-1edc-978a-e1d9-513b08695f89}]
2008-05-27 09:34 370688 --a------ C:\WINDOWS\system32\{35a6ae75-c06a-1fc9-e65b-9ee1f3540a3c}.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IBM RecordNow!"="" []
"tgcmd"="" []
"ibmmessages"="C:\Program Files\IBM\Messages By IBM\ibmmessages.exe" [2003-07-21 19:00 540672]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\ypager.exe" [2005-02-24 14:57 2506752]
"Uahe"="C:\PROGRA~1\COMMON~1\YSTEM3~1\dvdplay.exe" [ ]
"Dkdtq"="C:\Program Files\Common Files\W?nSxS\?explore.exe" [ ]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56 15360]
"QdrPack16"="C:\Program Files\QdrPack\QdrPack16.exe" [ ]
"QdrModule17"="C:\Program Files\QdrModule\QdrModule17.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-01-12 19:41 98304]
"McAfeeUpdaterUI"="C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" [2004-08-25 00:50 139320]
"ShStatEXE"="C:\Program Files\Network Associates\VirusScan\SHSTAT.exe" [2004-09-23 00:00 94208]
"Network Associates Error Reporting Service"="C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe" [2003-10-07 13:48 147514]
"UpdateManager"="c:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 05:01 110592]
"UC_Start"="C:\IBMTools\Updater\ucstartup.exe" [2003-03-17 19:27 32768]
"TpShocks"="TpShocks.exe" [2003-09-04 03:02 77824 C:\WINDOWS\system32\TpShocks.exe]
"TPKMAPHELPER"="C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe" [2003-09-02 17:56 897024]
"TPHOTKEY"="C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe" [2003-08-07 19:57 94208]
"TP4EX"="tp4ex.exe" [2002-09-04 05:05 53248 C:\WINDOWS\system32\TP4EX.exe]
"tgcmd"="" []
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2003-08-28 15:11 110592]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2003-08-28 15:10 512000]
"S3TRAY2"="S3Tray2.exe" [2001-10-12 03:32 69632 C:\WINDOWS\system32\S3Tray2.exe]
"QCWLICON"="C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE" [2003-10-11 06:07 53248]
"NAV CfgWiz"="C:\PROGRA~1\NORTON~1\Cfgwiz.exe" [ ]
"ibmmessages"="C:\Program Files\IBM\Messages By IBM\ibmmessages.exe" [2003-07-21 19:00 540672]
"EZEJMNAP"="C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [2003-07-18 06:02 208896]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2003-10-22 05:04 114741]
"ccRegVfy"="C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe" [ ]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [ ]
"BMMLREF"="C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE" [2003-07-11 05:34 20480]
"BMMGAG"="C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll" [2003-07-11 05:34 94208]
"BluetoothAuthenticationAgent"="irprops.cpl" [2004-08-04 03:56 380416 C:\WINDOWS\system32\irprops.cpl]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-09-12 01:10 335872]
"ATIModeChange"="Ati2mdxx.exe" [2001-09-04 20:24 28672 C:\WINDOWS\system32\Ati2mdxx.exe]
"AGRSMMSG"="AGRSMMSG.exe" [2003-06-27 12:53 88363 C:\WINDOWS\AGRSMMSG.exe]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2005-03-05 09:11 26112]
"mxomssmenu"="C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe" [2007-09-06 18:53 169264]
"{74-4C-CB-B9-DW}"="c:\windows\system32\rwwnw64d.exe" [ ]
"{c3f670a7-1bb7-5093-12d3-d28162845729}"="C:\WINDOWS\system32\{35a6ae75-c06a-1fc9-e65b-9ee1f3540a3c}.dll" [2008-05-27 09:34 370688]
"ExploreUpdSched"="C:\WINDOWS\system32\tcntaxdn.exe" [2008-05-27 19:43 200767]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
America Online 9.0 Tray Icon.lnk - C:\Program Files\America Online 9.0\aoltray.exe [2005-03-05 11:14:48 36954]
AOL Companion.lnk - C:\Program Files\AOL Companion\companion.exe [2005-03-05 11:16:49 229450]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\byXQGyab]
byXQGyab.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\America Online 9.0\\waol.exe"=
R0 Shockprf;Shockprf;C:\WINDOWS\system32\drivers\Shockprf.sys [2003-09-11 14:03]
R1 IBMTPCHK;IBMTPCHK;C:\WINDOWS\system32\drivers\IBMBLDID.SYS [2003-10-11 06:07]
R1 TPPWR;TPPWR;C:\WINDOWS\system32\drivers\Tppwr.sys [2003-07-11 05:34]
R2 Maxtor Sync Service;Maxtor Service;"C:\Program Files\Maxtor\Sync\SyncServices.exe" [2007-09-28 16:24]
R2 ShockMgr;ShockMgr;C:\WINDOWS\system32\drivers\ShockMgr.sys [2003-07-24 17:26]
S3 ANC;ANC;C:\WINDOWS\system32\drivers\ANC.SYS [2003-10-11 06:07]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{23460d10-da2a-11dc-b4f9-00038a000015}]
\Shell\Auto\command - E:\Start.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Start.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4c38c4e0-eea7-11db-b44f-00038a000015}]
\Shell\Auto\command - Start.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Start.exe
.
Contents of the 'Scheduled Tasks' folder
"2004-05-21 07:04:32 C:\WINDOWS\Tasks\BMMTask.job"
- C:\PROGRA~1\ThinkPad\UTILIT~1\BMMTASK.EXE
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-05-31 23:13:03
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\WINDOWS\system32\zxdnt3d.cfg 21 bytes
scan completed successfully
hidden files: 1
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\Ati2evxx.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\S24EvMon.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Patchlink\Update Agent\GravitixService.exe
C:\WINDOWS\system32\QCONSVC.EXE
C:\WINDOWS\system32\RegSrvc.exe
C:\WINDOWS\system32\TpKmpSvc.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\PROGRA~1\NETWOR~1\COMMON~1\naPrdMgr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Qoobox\Quarantine\C\WINDOWS\system32\rwwnw64d.exe.virft.VC8
C:\Program Files\Yahoo!\Messenger\Ymsgr_tray.exe
.
**************************************************************************
.
Completion time: 2008-05-31 23:18:45 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-01 03:18:38
Pre-Run: 16,899,358,720 bytes free
Post-Run: 16,874,016,768 bytes free
258 --- E O F --- 2008-05-16 00:57:31
--------------------------------------------------------------------------------
Get trade secrets for amazing burgers. Watch "Cooking with Tyler Florence" on AOL Food.