(The "Winlogon Trojan" folder is one I created myself)
"Wilson" - 07-01-20 11:41:24 Service Pack 2
ComboFix 07-01-18 - Running from: "C:\Winlogon Trojan"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\setup.exe
((((((((((((((((((((((((((((((( Files Created from 2006-12-20 to 2007-01-20 ))))))))))))))))))))))))))))))))))
2007-01-20 02:36 4,456 --a------ C:\WINDOWS\system32\tmp.reg
2007-01-19 21:56 <DIR> d-------- C:\Winlogon Trojan
2007-01-19 21:30 <DIR> d-------- C:\Program Files\Opera
2007-01-19 18:58 <DIR> d-------- C:\To-Do
2007-01-17 03:28 <DIR> d-------- C:\WINDOWS\WBEM
2007-01-17 03:28 <DIR> d-------- C:\WINDOWS\system32\en-US
2007-01-17 03:26 <DIR> d--h-c--- C:\WINDOWS\ie7
2007-01-17 03:24 121,856 --------- C:\WINDOWS\system32\xmllite.dll
2007-01-17 03:24 <DIR> d-------- C:\WINDOWS\network diagnostic
2007-01-16 15:38 <DIR> d-------- C:\Program Files\Apache Software Foundation
2007-01-15 23:12 <DIR> d--h----- C:\WINDOWS\PIF
2007-01-14 13:28 <DIR> d-------- C:\Program Files\Virtools Web Player 3.0
2007-01-03 23:26 295,001 --------- C:\WINDOWS\system32\ctjb2sp.dll
2007-01-03 23:26 28,672 --------- C:\WINDOWS\system32\PdeSrvps.dll
2007-01-03 23:26 149,504 --a------ C:\WINDOWS\UNWISE.EXE
2007-01-03 15:49 <DIR> d-------- C:\DOCUME~1\Wilson\Application Data\Creative
2007-01-03 15:05 41,984 --------- C:\WINDOWS\Ctregrun.exe
2007-01-03 15:05 24,576 --------- C:\WINDOWS\system32\msxml3a.dll
2007-01-03 15:04 <DIR> d-------- C:\Program Files\Audible
2007-01-03 15:01 <DIR> d--h----- C:\Program Files\Creative Installation Information
2007-01-03 14:59 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Creative
2007-01-03 14:57 <DIR> d-------- C:\Program Files\Creative
2006-12-30 22:09 <DIR> d-------- C:\Program Files\Winamp
2006-12-30 19:15 765,952 --a------ C:\WINDOWS\system32\xvidcore.dll
2006-12-30 19:15 180,224 --a------ C:\WINDOWS\system32\xvidvfw.dll
2006-12-30 19:15 <DIR> d-------- C:\Program Files\Xvid
2006-12-26 19:09 <DIR> d-------- C:\Media
2006-12-20 02:51 <DIR> d-------- C:\Program Files\Ubisoft
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-01-20 11:38 -------- d-------- C:\Program Files\mozilla firefox
2007-01-20 04:38 -------- d-------- C:\Program Files\mysql
2007-01-20 03:30 -------- d-------- C:\DOCUME~1\Wilson\Application Data\avg7
2007-01-20 02:14 -------- d-------- C:\Program Files\trillian
2007-01-19 18:52 -------- d-------- C:\Program Files\web publish
2007-01-17 15:50 -------- d-------- C:\Program Files\mozilla thunderbird
2007-01-14 04:09 -------- d-------- C:\DOCUME~1\Wilson\Application Data\mozilla
2007-01-13 23:15 -------- d-------- C:\DOCUME~1\Wilson\Application Data\adobeum
2007-01-06 12:18 -------- d-------- C:\Program Files\google
2007-01-03 23:31 -------- d--h----- C:\Program Files\installshield installation information
2007-01-03 23:16 -------- d-------- C:\Program Files\canon
2006-12-15 21:27 -------- d-------- C:\Program Files\notepad++
2006-12-15 20:50 -------- d-------- C:\DOCUME~1\Wilson\Application Data\gtek
2006-12-07 01:40 2362184 --a------ C:\WINDOWS\system32\wmvcore.dll
2006-12-04 18:40 -------- d-------- C:\Program Files\chm to pdf converter pro
2006-12-04 18:40 -------- d-------- C:\Program Files\abc amber chm converter
2006-12-02 17:20 -------- d-------- C:\Program Files\java
2006-12-02 16:56 -------- d-------- C:\Program Files\objectdb
2006-11-25 13:36 816672 --a------ C:\WINDOWS\system32\drivers\avg7core.sys
2006-11-25 13:36 4960 --a------ C:\WINDOWS\system32\drivers\avgtdi.sys
2006-11-25 13:36 4224 --a------ C:\WINDOWS\system32\drivers\avg7rsw.sys
2006-11-25 13:36 3968 --a------ C:\WINDOWS\system32\drivers\avgclean.sys
2006-11-25 13:36 28416 --a------ C:\WINDOWS\system32\drivers\avg7rsxp.sys
2006-11-25 13:36 18240 --a------ C:\WINDOWS\system32\drivers\avgmfx86.sys
2006-11-25 13:36 -------- d---s---- C:\DOCUME~1\Wilson\Application Data\microsoft
2006-11-08 00:06 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
2006-11-07 21:03 6049280 --------- C:\WINDOWS\system32\ieframe.dll
2006-11-07 21:03 50688 --------- C:\WINDOWS\system32\msfeedsbs.dll
2006-11-07 21:03 458752 --------- C:\WINDOWS\system32\msfeeds.dll
2006-11-07 21:03 413696 --a------ C:\WINDOWS\system32\vbscript.dll
2006-11-07 21:03 231424 --a------ C:\WINDOWS\system32\webcheck.dll
2006-11-07 21:03 180736 --------- C:\WINDOWS\system32\ieui.dll
2006-11-07 21:03 156160 --a------ C:\WINDOWS\system32\msls31.dll
2006-11-07 03:27 382976 --a------ C:\WINDOWS\system32\iedkcs32.dll
2006-11-07 03:27 229376 --a------ C:\WINDOWS\system32\ieaksie.dll
2006-11-07 03:26 71680 --a------ C:\WINDOWS\system32\admparse.dll
2006-11-07 03:26 55296 --a------ C:\WINDOWS\system32\iesetup.dll
2006-11-07 03:26 54784 --a------ C:\WINDOWS\system32\ie4uinit.exe
2006-11-07 03:26 43008 --a------ C:\WINDOWS\system32\iernonce.dll
2006-11-07 03:26 152064 --a------ C:\WINDOWS\system32\ieakeng.dll
2006-11-07 03:26 13312 --a------ C:\WINDOWS\system32\ieudinit.exe
2006-11-07 03:26 123904 --a------ C:\WINDOWS\system32\advpack.dll
2006-11-07 03:25 161792 --a------ C:\WINDOWS\system32\ieakui.dll
2006-11-04 14:14 1245696 --a------ C:\WINDOWS\system32\msxml4.dll
2006-10-29 01:44 47336 --a------ C:\DOCUME~1\Wilson\Application Data\gdipfontcachev1.dat
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.908.6962\\GoogleToolbarNotifier.exe"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"Apoint"="C:\\Program Files\\Apoint\\Apoint.exe"
"Mouse Suite 98 Daemon"="ICO.EXE"
"VAIO Recovery"="C:\\WINDOWS\\Sonysys\\VAIO Recovery\\PartSeal.exe"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_10\\bin\\jusched.exe\""
"SonyPowerCfg"="C:\\Program Files\\Sony\\VAIO Power Management\\SPMgr.exe"
"AzMixerSel"="C:\\Program Files\\Realtek\\InstallShield\\AzMixerSel.exe"
"ISBMgr.exe"="C:\\Program Files\\Sony\\ISB Utility\\ISBMgr.exe"
"VAIO Update 2"="\"C:\\Program Files\\Sony\\VAIO Update 2\\VAIOUpdt.exe\" /Stationary"
"IgfxTray"="C:\\WINDOWS\\system32\\igfxtray.exe"
"HotKeysCmds"="C:\\WINDOWS\\system32\\hkcmd.exe"
"Persistence"="C:\\WINDOWS\\system32\\igfxpers.exe"
"PartSeal"="C:\\WINDOWS\\Sonysys\\VAIO Recovery\\PartSeal.exe"
"SsAAD.exe"="C:\\PROGRA~1\\Sony\\SONICS~1\\SsAAD.exe"
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE"
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
@=""
"Google Desktop Search"="\"C:\\Program Files\\Google\\Google Desktop Search\\GoogleDesktop.exe\" /startup"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
"Zone Labs Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\""
"googletalk"="C:\\Program Files\\Google\\Google Talk\\googletalk.exe /autostart"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="issch"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Common Files\\InstallShield\\UpdateService\\issch.exe\" -start"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"appinit_dlls"="C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoCDBurning"=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
~ ~ ~ ~ ~ ~ ~ ~ Hijackthis Backups ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
backup-20070119-144217-483
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
backup-20070119-144041-504
O11 - Options group: [INTERNATIONAL] International*
backup-20070119-141915-403
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712...
backup-20070119-141915-581
O23 - Service: MySQL - Unknown owner - C:\Program.exe (file missing)
backup-20070119-141914-533
O16 - DPF: {3CF0D111-6B4B-11D2-954A-525400D9564E} (DataConst Control) - http://www.qcwireless.net/kluwer/c9...
backup-20070119-141914-393
O16 - DPF: {27DA7223-9574-11D3-9798-00105AAACF8C} (PDInferPanelX Control) - http://www.qcwireless.net/kluwer/c9...
backup-20070119-141914-197
O16 - DPF: {25365FF3-2746-4230-9DA7-163CCA318309} (Automatic Driver Installation Control) - http://inst.c-wss.com/n024p/EN/inst...
backup-20070119-141914-375
O15 - Trusted Zone: http://www.qcwireless.net
backup-20070119-141914-124
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
backup-20070119-141914-789
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
backup-20070119-140145-608
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
Completion time: 07-01-20 11:47:38