And here are the CF and HTJ logs. This trojan is one of the most stubborn I have encountered.
ComboFix 08-01-23.1 - Christian Rooney 2008-01-24 10:38:02.9 - NTFSx86
Running from: C:\Documents and Settings\Christian Rooney\Desktop\HJT\ComboFix.exe
Command switches used :: C:\Documents and Settings\Christian Rooney\Desktop\HJT\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\ctfmon.exe.tmp
C:\WINDOWS\system32\kknnn.ini
C:\WINDOWS\system32\kknnn.ini2
C:\WINDOWS\system32\nnnkk.dll
C:\WINDOWS\system32\nnnkk.exe
.
---- Previous Run -------
.
C:\WINDOWS\system32\kknnn.ini
C:\WINDOWS\system32\kknnn.ini2
C:\WINDOWS\system32\nnnkk.dll
C:\WINDOWS\system32\nnnkk.exe
.
((((((((((((((((((((((((( Files Created from 2007-12-24 to 2008-01-24 )))))))))))))))))))))))))))))))
.
2008-01-24 10:56 . 2008-01-24 10:56 338,432 --a------ C:\WINDOWS\system32\nnnkk.exe
2008-01-24 10:55 . 2008-01-24 10:55 334,848 --------- C:\WINDOWS\system32\nnnkk.dll
2008-01-24 10:28 . 2008-01-24 10:28 15,360 --a--c--- C:\WINDOWS\system32\dllcache\ctfmon.exe
2008-01-24 10:28 . 2008-01-24 10:28 15,360 --a------ C:\WINDOWS\system32\ctfmon.exe
2008-01-23 20:06 . 2008-01-23 20:06 <DIR> d-------- C:\Program Files\Common Files\ACD Systems
2008-01-23 20:06 . 2008-01-23 20:06 <DIR> d-------- C:\Program Files\ACD Systems
2008-01-23 05:44 . 2008-01-23 05:44 <DIR> d-------- C:\Program Files\Destiny
2008-01-22 11:33 . 2008-01-22 11:33 <DIR> d-------- C:\tmpDownload
2008-01-22 11:29 . 2008-01-22 11:33 <DIR> d-------- C:\Program Files\YoutubeGet
2008-01-22 11:29 . 2008-01-22 11:29 253,952 --a------ C:\WINDOWS\system32\andt.sys
2008-01-22 11:29 . 2008-01-22 11:29 45,056 --a------ C:\WINDOWS\system32\Indt2.sys
2008-01-22 11:29 . 2008-01-22 11:29 40 --a------ C:\WINDOWS\system32\drmgs.sys
2008-01-22 08:47 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\Nircmd.exe
2008-01-21 21:04 . 2008-01-21 21:04 <DIR> d-------- C:\Program Files\Maxis
2008-01-21 20:53 . 2008-01-21 20:53 <DIR> d-------- C:\Program Files\Alcohol Soft
2008-01-21 17:45 . 2008-01-21 17:45 <DIR> d-------- C:\Program Files\Dot1XCfg
2008-01-21 14:07 . 2008-01-21 19:49 715,248 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2008-01-20 06:06 . 2008-01-20 06:06 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-01-20 06:06 . 2008-01-20 06:06 1,744 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-01-20 06:06 . 2008-01-20 06:06 1,409 --a------ C:\WINDOWS\QTFont.for
2007-12-30 22:56 . 1998-10-01 15:22 299,520 --a------ C:\WINDOWS\uninst.exe
2007-12-29 18:17 . 2007-12-29 18:17 <DIR> d-------- C:\WINDOWS\Cache
2007-12-29 18:17 . 2007-12-31 10:09 <DIR> d-------- C:\Program Files\Coupons
2007-12-25 00:58 . 2007-12-25 00:58 <DIR> d-------- C:\Program Files\QuickTime Alternative
2007-12-25 00:58 . 2007-12-11 10:57 65,536 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
2007-12-25 00:58 . 2007-12-11 10:57 49,152 --a------ C:\WINDOWS\system32\QuickTime.qts
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-24 11:23 --------- d-----w C:\Program Files\Azureus
2008-01-05 01:43 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-05 01:43 --------- d-----w C:\Program Files\CyberLink DVD Solution
2008-01-05 01:41 --------- d-----w C:\Program Files\Common Files\Adobe
2007-12-23 03:23 --------- d-----w C:\Program Files\Ultra Video Splitter
2007-12-23 02:33 --------- d-----w C:\Program Files\Absolute Video Splitter Joiner
2007-12-22 20:17 --------- d-----w C:\Program Files\K-Lite Codec Pack
2007-12-22 20:00 --------- d-----w C:\Program Files\Common Files\Real
2007-12-19 01:02 39,424 ----a-w C:\WINDOWS\zipinst.exe
2007-12-15 09:11 --------- d-----w C:\Program Files\Common Files\Macrovision Shared
2007-12-15 06:10 --------- d-----w C:\Program Files\LimeWire
2007-12-14 03:10 --------- d-----w C:\Program Files\Common Files\Ahead
2007-12-14 03:07 --------- d-----w C:\Program Files\Nero
2007-12-10 04:30 --------- d-----w C:\Program Files\iolo
2007-12-10 04:04 668,160 ----a-w C:\WINDOWS\is-6SPB2.exe
2007-12-08 07:50 --------- d-----w C:\Program Files\VideoLAN
2007-12-07 23:28 7,680 ----a-w C:\WINDOWS\system32\ff_vfw.dll
2007-12-04 07:33 682,496 ----a-w C:\WINDOWS\system32\divx.dll
2007-11-30 04:30 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2007-11-30 04:28 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\system32\lsasrv.dll
2007-11-03 16:46 363,368 ----a-w C:\WINDOWS\system32\Incinerator.dll
2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-27 22:40 227,328 ----a-w C:\WINDOWS\system32\wmasf.dll
2004-10-01 20:00 40,960 ----a-w C:\Program Files\Uninstall_CDS.exe
.
((((((((((((((((((((((((((((( snapshot@2008-01-22_22.52.53.67 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-22 13:48:55 1,413,120 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
+ 2008-01-24 15:36:33 1,413,120 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
- 2008-01-22 13:48:55 1,196,032 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
+ 2008-01-24 15:36:33 1,196,032 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
- 2008-01-22 13:48:55 4,423,680 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
+ 2008-01-24 15:36:34 4,734,976 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
- 2008-01-22 13:48:55 1,335,296 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
+ 2008-01-24 15:36:34 1,335,296 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
- 2008-01-22 13:48:55 1,413,120 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
+ 2008-01-24 15:36:34 1,413,120 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
- 2008-01-22 13:48:56 1,196,032 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
+ 2008-01-24 15:36:35 1,196,032 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
+ 2008-01-24 01:11:08 249,856 ----a-r C:\WINDOWS\Installer\{1A103C8B-3DFA-4F05-BE9B-97B7ECC12925}\ARPPRODUCTICON.exe
+ 2008-01-24 01:11:09 344,064 ----a-r C:\WINDOWS\Installer\{1A103C8B-3DFA-4F05-BE9B-97B7ECC12925}\NewShortcut1_1A103C8B3DFA4F05BE9B97B7ECC12925_1.exe
+ 2008-01-24 01:11:09 344,064 ----a-r C:\WINDOWS\Installer\{1A103C8B-3DFA-4F05-BE9B-97B7ECC12925}\NewShortcut2_1A103C8B3DFA4F05BE9B97B7ECC12925_1.exe
+ 2008-01-24 01:11:08 249,856 ----a-r C:\WINDOWS\Installer\{1A103C8B-3DFA-4F05-BE9B-97B7ECC12925}\NewShortcut5_1A103C8B3DFA4F05BE9B97B7ECC12925.exe
+ 2008-01-24 01:11:09 249,856 ----a-r C:\WINDOWS\Installer\{1A103C8B-3DFA-4F05-BE9B-97B7ECC12925}\NewShortcut6_1A103C8B3DFA4F05BE9B97B7ECC12925.exe
+ 2002-01-05 08:40:20 487,424 ----a-w C:\WINDOWS\system32\msvcp70.dll
+ 2002-01-05 08:37:28 344,064 ----a-w C:\WINDOWS\system32\msvcr70.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AE77594E-D03D-4C35-BA5B-A94A1AF766CE}]
2008-01-24 10:55 334848 --------- C:\WINDOWS\system32\nnnkk.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2008-01-24 10:38 588288]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-01-24 10:28 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2008-01-24 10:38 475136]
"InCD"="C:\Program Files\Ahead\InCD\InCD.exe" [2008-01-24 10:38 1890816]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2008-01-24 10:56 495104]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2008-01-24 10:38 588288]
"Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-01-24 10:38 969216]
"combofix"="C:\WINDOWS\system32\cmd.exe" [2004-08-04 07:00 388608]
[HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\windows]
"load"=C:\WINDOWS\system32\nnnkk.exe
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 C:\WINDOWS\system32\nnnkk
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{30803c20-b89a-11dc-bd5f-00e018304548}]
\Shell\AutoRun\command - G:\Autoplay.exe -auto
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-24 10:56:51
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.3156]
-> C:\WINDOWS\system32\nnnkk.dll
.
Completion time: 2008-01-24 11:02:38 - machine was rebooted [Christian Rooney]
ComboFix-quarantined-files.txt 2008-01-24 16:02:23
ComboFix2.txt 2008-01-24 09:38:40
ComboFix3.txt 2008-01-23 14:12:33
ComboFix4.txt 2008-01-23 04:38:36
ComboFix5.txt 2008-01-23 03:54:20
.
2008-01-09 01:40:01 --- E O F ---
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:05:56 AM, on 1/24/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\iolo\Common\Lib\ioloDMVSvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\Ahead\InCD\InCD .exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection .exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched .exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray .exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Christian Rooney\Desktop\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
F3 - REG:win.ini: load=C:\WINDOWS\system32\nnnkk.exe
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {54BE6B6F-3056-470B-97E1-BB92E051B6C4} (DeviceEnum Class) - http://h30155.www3.hp.com/ediags/dd/install/HPDriverDiagnosticsxp2k.cab
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://www.auctiva.com/hostedimages/activex/xupload/XUpload.ocx
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iolo DMV Service (ioloDMV) - Unknown owner - C:\Program Files\iolo\Common\Lib\ioloDMVSvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
--
End of file - 7270 bytes
ComboFix 08-01-23.1 - Christian Rooney 2008-01-24 10:38:02.9 - NTFSx86
Running from: C:\Documents and Settings\Christian Rooney\Desktop\HJT\ComboFix.exe
Command switches used :: C:\Documents and Settings\Christian Rooney\Desktop\HJT\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\ctfmon.exe.tmp
C:\WINDOWS\system32\kknnn.ini
C:\WINDOWS\system32\kknnn.ini2
C:\WINDOWS\system32\nnnkk.dll
C:\WINDOWS\system32\nnnkk.exe
.
---- Previous Run -------
.
C:\WINDOWS\system32\kknnn.ini
C:\WINDOWS\system32\kknnn.ini2
C:\WINDOWS\system32\nnnkk.dll
C:\WINDOWS\system32\nnnkk.exe
.
((((((((((((((((((((((((( Files Created from 2007-12-24 to 2008-01-24 )))))))))))))))))))))))))))))))
.
2008-01-24 10:56 . 2008-01-24 10:56 338,432 --a------ C:\WINDOWS\system32\nnnkk.exe
2008-01-24 10:55 . 2008-01-24 10:55 334,848 --------- C:\WINDOWS\system32\nnnkk.dll
2008-01-24 10:28 . 2008-01-24 10:28 15,360 --a--c--- C:\WINDOWS\system32\dllcache\ctfmon.exe
2008-01-24 10:28 . 2008-01-24 10:28 15,360 --a------ C:\WINDOWS\system32\ctfmon.exe
2008-01-23 20:06 . 2008-01-23 20:06 <DIR> d-------- C:\Program Files\Common Files\ACD Systems
2008-01-23 20:06 . 2008-01-23 20:06 <DIR> d-------- C:\Program Files\ACD Systems
2008-01-23 05:44 . 2008-01-23 05:44 <DIR> d-------- C:\Program Files\Destiny
2008-01-22 11:33 . 2008-01-22 11:33 <DIR> d-------- C:\tmpDownload
2008-01-22 11:29 . 2008-01-22 11:33 <DIR> d-------- C:\Program Files\YoutubeGet
2008-01-22 11:29 . 2008-01-22 11:29 253,952 --a------ C:\WINDOWS\system32\andt.sys
2008-01-22 11:29 . 2008-01-22 11:29 45,056 --a------ C:\WINDOWS\system32\Indt2.sys
2008-01-22 11:29 . 2008-01-22 11:29 40 --a------ C:\WINDOWS\system32\drmgs.sys
2008-01-22 08:47 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\Nircmd.exe
2008-01-21 21:04 . 2008-01-21 21:04 <DIR> d-------- C:\Program Files\Maxis
2008-01-21 20:53 . 2008-01-21 20:53 <DIR> d-------- C:\Program Files\Alcohol Soft
2008-01-21 17:45 . 2008-01-21 17:45 <DIR> d-------- C:\Program Files\Dot1XCfg
2008-01-21 14:07 . 2008-01-21 19:49 715,248 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2008-01-20 06:06 . 2008-01-20 06:06 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-01-20 06:06 . 2008-01-20 06:06 1,744 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-01-20 06:06 . 2008-01-20 06:06 1,409 --a------ C:\WINDOWS\QTFont.for
2007-12-30 22:56 . 1998-10-01 15:22 299,520 --a------ C:\WINDOWS\uninst.exe
2007-12-29 18:17 . 2007-12-29 18:17 <DIR> d-------- C:\WINDOWS\Cache
2007-12-29 18:17 . 2007-12-31 10:09 <DIR> d-------- C:\Program Files\Coupons
2007-12-25 00:58 . 2007-12-25 00:58 <DIR> d-------- C:\Program Files\QuickTime Alternative
2007-12-25 00:58 . 2007-12-11 10:57 65,536 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
2007-12-25 00:58 . 2007-12-11 10:57 49,152 --a------ C:\WINDOWS\system32\QuickTime.qts
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-24 11:23 --------- d-----w C:\Program Files\Azureus
2008-01-05 01:43 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-05 01:43 --------- d-----w C:\Program Files\CyberLink DVD Solution
2008-01-05 01:41 --------- d-----w C:\Program Files\Common Files\Adobe
2007-12-23 03:23 --------- d-----w C:\Program Files\Ultra Video Splitter
2007-12-23 02:33 --------- d-----w C:\Program Files\Absolute Video Splitter Joiner
2007-12-22 20:17 --------- d-----w C:\Program Files\K-Lite Codec Pack
2007-12-22 20:00 --------- d-----w C:\Program Files\Common Files\Real
2007-12-19 01:02 39,424 ----a-w C:\WINDOWS\zipinst.exe
2007-12-15 09:11 --------- d-----w C:\Program Files\Common Files\Macrovision Shared
2007-12-15 06:10 --------- d-----w C:\Program Files\LimeWire
2007-12-14 03:10 --------- d-----w C:\Program Files\Common Files\Ahead
2007-12-14 03:07 --------- d-----w C:\Program Files\Nero
2007-12-10 04:30 --------- d-----w C:\Program Files\iolo
2007-12-10 04:04 668,160 ----a-w C:\WINDOWS\is-6SPB2.exe
2007-12-08 07:50 --------- d-----w C:\Program Files\VideoLAN
2007-12-07 23:28 7,680 ----a-w C:\WINDOWS\system32\ff_vfw.dll
2007-12-04 07:33 682,496 ----a-w C:\WINDOWS\system32\divx.dll
2007-11-30 04:30 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2007-11-30 04:28 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\system32\lsasrv.dll
2007-11-03 16:46 363,368 ----a-w C:\WINDOWS\system32\Incinerator.dll
2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-27 22:40 227,328 ----a-w C:\WINDOWS\system32\wmasf.dll
2004-10-01 20:00 40,960 ----a-w C:\Program Files\Uninstall_CDS.exe
.
Code:
<pre>
----a-w 624,248 2008-01-24 15:55:38 C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray .exe
----a-w 1,397,760 2008-01-24 15:55:35 C:\Program Files\Ahead\InCD\InCD .exe
----a-w 155,648 2008-01-24 15:55:32 C:\Program Files\Common Files\Ahead\Lib\NeroCheck .exe
----a-w 132,496 2008-01-24 15:55:29 C:\Program Files\Java\jre1.6.0_03\bin\jusched .exe
----a-w 224,248 2008-01-24 15:55:33 C:\Program Files\Yahoo!\Search Protection\SearchProtection .exe
</pre>
((((((((((((((((((((((((((((( snapshot@2008-01-22_22.52.53.67 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-22 13:48:55 1,413,120 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
+ 2008-01-24 15:36:33 1,413,120 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
- 2008-01-22 13:48:55 1,196,032 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
+ 2008-01-24 15:36:33 1,196,032 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
- 2008-01-22 13:48:55 4,423,680 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
+ 2008-01-24 15:36:34 4,734,976 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
- 2008-01-22 13:48:55 1,335,296 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
+ 2008-01-24 15:36:34 1,335,296 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
- 2008-01-22 13:48:55 1,413,120 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
+ 2008-01-24 15:36:34 1,413,120 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
- 2008-01-22 13:48:56 1,196,032 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
+ 2008-01-24 15:36:35 1,196,032 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
+ 2008-01-24 01:11:08 249,856 ----a-r C:\WINDOWS\Installer\{1A103C8B-3DFA-4F05-BE9B-97B7ECC12925}\ARPPRODUCTICON.exe
+ 2008-01-24 01:11:09 344,064 ----a-r C:\WINDOWS\Installer\{1A103C8B-3DFA-4F05-BE9B-97B7ECC12925}\NewShortcut1_1A103C8B3DFA4F05BE9B97B7ECC12925_1.exe
+ 2008-01-24 01:11:09 344,064 ----a-r C:\WINDOWS\Installer\{1A103C8B-3DFA-4F05-BE9B-97B7ECC12925}\NewShortcut2_1A103C8B3DFA4F05BE9B97B7ECC12925_1.exe
+ 2008-01-24 01:11:08 249,856 ----a-r C:\WINDOWS\Installer\{1A103C8B-3DFA-4F05-BE9B-97B7ECC12925}\NewShortcut5_1A103C8B3DFA4F05BE9B97B7ECC12925.exe
+ 2008-01-24 01:11:09 249,856 ----a-r C:\WINDOWS\Installer\{1A103C8B-3DFA-4F05-BE9B-97B7ECC12925}\NewShortcut6_1A103C8B3DFA4F05BE9B97B7ECC12925.exe
+ 2002-01-05 08:40:20 487,424 ----a-w C:\WINDOWS\system32\msvcp70.dll
+ 2002-01-05 08:37:28 344,064 ----a-w C:\WINDOWS\system32\msvcr70.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AE77594E-D03D-4C35-BA5B-A94A1AF766CE}]
2008-01-24 10:55 334848 --------- C:\WINDOWS\system32\nnnkk.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2008-01-24 10:38 588288]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-01-24 10:28 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2008-01-24 10:38 475136]
"InCD"="C:\Program Files\Ahead\InCD\InCD.exe" [2008-01-24 10:38 1890816]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2008-01-24 10:56 495104]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2008-01-24 10:38 588288]
"Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-01-24 10:38 969216]
"combofix"="C:\WINDOWS\system32\cmd.exe" [2004-08-04 07:00 388608]
[HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\windows]
"load"=C:\WINDOWS\system32\nnnkk.exe
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 C:\WINDOWS\system32\nnnkk
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{30803c20-b89a-11dc-bd5f-00e018304548}]
\Shell\AutoRun\command - G:\Autoplay.exe -auto
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-24 10:56:51
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.3156]
-> C:\WINDOWS\system32\nnnkk.dll
.
Completion time: 2008-01-24 11:02:38 - machine was rebooted [Christian Rooney]
ComboFix-quarantined-files.txt 2008-01-24 16:02:23
ComboFix2.txt 2008-01-24 09:38:40
ComboFix3.txt 2008-01-23 14:12:33
ComboFix4.txt 2008-01-23 04:38:36
ComboFix5.txt 2008-01-23 03:54:20
.
2008-01-09 01:40:01 --- E O F ---
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:05:56 AM, on 1/24/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\iolo\Common\Lib\ioloDMVSvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\Ahead\InCD\InCD .exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection .exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched .exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray .exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Christian Rooney\Desktop\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
F3 - REG:win.ini: load=C:\WINDOWS\system32\nnnkk.exe
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {54BE6B6F-3056-470B-97E1-BB92E051B6C4} (DeviceEnum Class) - http://h30155.www3.hp.com/ediags/dd/install/HPDriverDiagnosticsxp2k.cab
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://www.auctiva.com/hostedimages/activex/xupload/XUpload.ocx
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iolo DMV Service (ioloDMV) - Unknown owner - C:\Program Files\iolo\Common\Lib\ioloDMVSvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
--
End of file - 7270 bytes