Here Combofix log
ComboFix 08-02-14.2 - xyz 2008-02-16 22:08:13.1 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.80 [GMT 5.5:30]
Running from: C:\Documents and Settings\xyz\My Documents\My Completed Downloads\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\3721
C:\Program Files\3721\assist\asbar.dll
C:\Program Files\3721\helper.dll
C:\Program Files\Accoona
C:\Program Files\Accoona\ASearchAssist.dll
C:\Program Files\akl
C:\Program Files\akl\akl.dll
C:\Program Files\akl\akl.exe
C:\Program Files\akl\curlog.htm
C:\Program Files\akl\keylog.txt
C:\Program Files\akl\readme.txt
C:\Program Files\akl\uninstall.exe
C:\Program Files\akl\unsetup.dat
C:\Program Files\akl\unsetup.exe
C:\Program Files\amsys
C:\Program Files\amsys\awmsg.dat
C:\Program Files\amsys\guid.dat
C:\Program Files\amsys\ijl15.dll
C:\Program Files\amsys\mfc42.dll
C:\Program Files\amsys\msvcrt.dll
C:\Program Files\amsys\unins000.dat
C:\Program Files\amsys\unis000.exe
C:\Program Files\amsys\winam.dat
C:\Program Files\e-zshopper
C:\Program Files\e-zshopper\BarLcher.dll
C:\WINDOWS\7search.dll
C:\WINDOWS\absolute key logger.lnk
C:\WINDOWS\aconti.exe
C:\WINDOWS\aconti.ini
C:\WINDOWS\aconti.log
C:\WINDOWS\aconti.sdb
C:\WINDOWS\acontidialer.txt
C:\WINDOWS\adbar.dll
C:\WINDOWS\cbinst$.exe
C:\WINDOWS\daxtime.dll
C:\WINDOWS\dp0.dll
C:\WINDOWS\eventlowg.dll
C:\WINDOWS\fhfmm-Uninstaller.exe
C:\WINDOWS\fhfmm.exe
C:\WINDOWS\flt.dll
C:\WINDOWS\hcwprn.exe
C:\WINDOWS\hotporn.exe
C:\WINDOWS\ie_32.exe
C:\WINDOWS\iexplorr23.dll
C:\WINDOWS\jd2002.dll
C:\WINDOWS\kkcomp$.exe
C:\WINDOWS\kkcomp.dll
C:\WINDOWS\kkcomp.exe
C:\WINDOWS\kvnab$.exe
C:\WINDOWS\kvnab.dll
C:\WINDOWS\kvnab.exe
C:\WINDOWS\liqad$.exe
C:\WINDOWS\liqad.dll
C:\WINDOWS\liqad.exe
C:\WINDOWS\liqui-Uninstaller.exe
C:\WINDOWS\liqui.dll
C:\WINDOWS\liqui.exe
C:\WINDOWS\msettings.ini
C:\WINDOWS\mywinsys.ini
C:\WINDOWS\ngd.dll
C:\WINDOWS\pbar.dll
C:\WINDOWS\pbsysie.dll
C:\WINDOWS\settn.dll
C:\WINDOWS\spredirect.dll
C:\WINDOWS\system32\8_exception.nls
C:\WINDOWS\system32\ace16win.dll
C:\WINDOWS\system32\acespy
C:\WINDOWS\system32\acespy\__acelog.ndx
C:\WINDOWS\system32\acespy\systune.exe
C:\WINDOWS\system32\din.ip
C:\WINDOWS\system32\drivers\bg_bg.gif
C:\WINDOWS\system32\drivers\blank.gif
C:\WINDOWS\system32\drivers\box_1.gif
C:\WINDOWS\system32\drivers\box_2.gif
C:\WINDOWS\system32\drivers\box_3.gif
C:\WINDOWS\system32\drivers\button_buynow.gif
C:\WINDOWS\system32\drivers\button_freescan.gif
C:\WINDOWS\system32\drivers\cell_bg.gif
C:\WINDOWS\system32\drivers\cell_footer.gif
C:\WINDOWS\system32\drivers\cell_header_block.gif
C:\WINDOWS\system32\drivers\cell_header_remove.gif
C:\WINDOWS\system32\drivers\cell_header_scan.gif
C:\WINDOWS\system32\drivers\close_ico.gif
C:\WINDOWS\system32\drivers\detect.htm
C:\WINDOWS\system32\drivers\download_box.gif
C:\WINDOWS\system32\drivers\download_btn.jpg
C:\WINDOWS\system32\drivers\download_now_btn.gif
C:\WINDOWS\system32\drivers\footer_back.jpg
C:\WINDOWS\system32\drivers\header_1.gif
C:\WINDOWS\system32\drivers\header_2.gif
C:\WINDOWS\system32\drivers\header_3.gif
C:\WINDOWS\system32\drivers\header_4.gif
C:\WINDOWS\system32\drivers\header_red_bg.gif
C:\WINDOWS\system32\drivers\header_red_free_scan.gif
C:\WINDOWS\system32\drivers\header_red_free_scan_bg.gif
C:\WINDOWS\system32\drivers\header_red_protect_your_pc.gif
C:\WINDOWS\system32\drivers\icon_warning_big.gif
C:\WINDOWS\system32\drivers\infected.gif
C:\WINDOWS\system32\drivers\main_back.gif
C:\WINDOWS\system32\drivers\perfect_cleaner_box.jpg
C:\WINDOWS\system32\drivers\product_1_header.gif
C:\WINDOWS\system32\drivers\product_1_name_small.gif
C:\WINDOWS\system32\drivers\product_2_header.gif
C:\WINDOWS\system32\drivers\product_2_name_small.gif
C:\WINDOWS\system32\drivers\product_3_header.gif
C:\WINDOWS\system32\drivers\product_3_name_small.gif
C:\WINDOWS\system32\drivers\product_features.gif
C:\WINDOWS\system32\drivers\pt.htm
C:\WINDOWS\system32\drivers\rating.gif
C:\WINDOWS\system32\drivers\remove_spyware_header.gif
C:\WINDOWS\system32\drivers\s_detect.htm
C:\WINDOWS\system32\drivers\screenshot.jpg
C:\WINDOWS\system32\drivers\sep_hor.gif
C:\WINDOWS\system32\drivers\sep_vert.gif
C:\WINDOWS\system32\drivers\shadow.jpg
C:\WINDOWS\system32\drivers\shadow_bg.gif
C:\WINDOWS\system32\drivers\spacer.gif
C:\WINDOWS\system32\drivers\spy_away_box.jpg
C:\WINDOWS\system32\drivers\spyware_detected.gif
C:\WINDOWS\system32\drivers\star.gif
C:\WINDOWS\system32\drivers\star_gray.gif
C:\WINDOWS\system32\drivers\star_gray_small.gif
C:\WINDOWS\system32\drivers\star_small.gif
C:\WINDOWS\system32\drivers\style.css
C:\WINDOWS\system32\drivers\v.gif
C:\WINDOWS\system32\drivers\warning_ico.gif
C:\WINDOWS\system32\drivers\warning_icon.gif
C:\WINDOWS\system32\drivers\win_logo.gif
C:\WINDOWS\system32\drivers\x.gif
C:\WINDOWS\system32\drivers\yellow_warning_ico.gif
C:\WINDOWS\system32\ESHOPEE.exe
C:\WINDOWS\system32\gtv_sd.bin
C:\WINDOWS\system32\msole32.exe
C:\WINDOWS\system32\mywebhit.ini
C:\WINDOWS\system32\mywebhit.ini.tmp
C:\WINDOWS\system32\stfv.bin
C:\WINDOWS\system32\sznf.ascii
C:\WINDOWS\system32\vxddsk.exe
C:\WINDOWS\system32\wml.exe
C:\WINDOWS\vxddsk.exe
C:\WINDOWS\wbeCheck.exe
C:\WINDOWS\wbeInst$.exe
C:\WINDOWS\wml.exe
C:\WINDOWS\xadbrk.dll
C:\WINDOWS\xadbrk.exe
C:\WINDOWS\xadbrk_.exe
C:\WINDOWS\xxxvideo.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Indexingbox
-------\nm
-------\runtime
((((((((((((((((((((((((( Files Created from 2008-01-16 to 2008-02-16 )))))))))))))))))))))))))))))))
.
2008-02-16 22:04 . 2008-02-16 22:05 <DIR> d-------- C:\Documents and Settings\xyz\Application Data\AVG7
2008-02-16 22:04 . 2008-02-16 22:04 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-02-16 22:04 . 2008-02-16 22:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg7
2008-02-15 16:42 . 2008-02-15 16:42 <DIR> d-------- C:\Program Files\Trend Micro
2008-02-13 18:44 . 2008-02-13 18:44 33,792 --a------ C:\msntznpz.exe
2008-02-13 15:52 . 2008-02-13 15:52 <DIR> d-------- C:\Documents and Settings\xyz\Application Data\F-Secure
2008-02-13 15:22 . 2008-02-13 15:22 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\F-Secure
2008-02-13 15:21 . 2008-02-13 15:21 <DIR> d-------- C:\Program Files\F-Secure Internet Security
2008-02-13 15:21 . 2008-02-13 15:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\fssg
2008-02-13 14:58 . 2008-02-13 14:58 <DIR> d-------- C:\Keat
2008-02-13 14:58 . 2006-03-01 19:45 345,604 --a------ C:\WINDOWS\system32\msinfhlp.exe
2008-02-13 14:58 . 1998-06-16 00:00 132,224 --a------ C:\WINDOWS\system32\vjreg.exe
2008-02-12 12:30 . 2008-02-12 12:30 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-12 10:46 . 2008-02-12 10:46 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PC Tools
2008-02-12 10:46 . 2008-02-08 10:45 12,608 --a------ C:\WINDOWS\system32\drivers\TfKbMon.sys
2008-02-12 09:54 . 2008-02-12 09:54 <DIR> d-------- C:\Program Files\Protea AntiVirus Tools
2008-02-11 21:26 . 2008-02-11 21:26 15,872 --a------ C:\WINDOWS\system32\drvmif.dll
2008-02-11 19:31 . 2008-02-11 19:31 24,576 --a------ C:\WINDOWS\system32\winwea32.dll
2008-02-11 19:29 . 2008-02-11 19:30 24,064 --a------ C:\WINDOWS\system32\winmyy32.dll
2008-02-11 19:29 . 2008-02-11 19:29 24,064 --a------ C:\WINDOWS\system32\winjyg32.dll
2008-01-27 14:21 . 2008-01-27 14:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Google Updater
2008-01-20 20:07 . 2008-01-20 20:07 <DIR> d-------- C:\Program Files\Atomic Superball DEMO
2008-01-20 20:07 . 2008-01-21 10:50 26 --a------ C:\WINDOWS\amx.ini
2008-01-19 16:07 . 2008-01-19 16:07 166 --a------ C:\key.shm
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-09 15:46 --------- d-----w C:\Documents and Settings\xyz\Application Data\Microsoft Web Folders
2008-01-05 10:54 971,232 ----a-w C:\WINDOWS\dbplugin.exe
2008-01-05 10:54 356,352 ----a-w C:\WINDOWS\eSellerateEngine.dll
2008-01-05 10:54 31,984 ----a-w C:\WINDOWS\dbrmdwb.exe
2008-01-05 10:54 2,323,952 ----a-w C:\WINDOWS\npdbplug.dll
2008-01-05 10:54 163,920 ----a-w C:\WINDOWS\system32\DNLEng.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\hliniy]
@={9026F10D-22A8-5B7A-0650-EEDDA383B216}
[HKEY_CLASSES_ROOT\CLSID\{9026F10D-22A8-5B7A-0650-EEDDA383B216}]
2004-09-01 00:00 71168 --a------ C:\WINDOWS\system32\hliniy.dIl
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-12-23 18:05 143360]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-09-01 00:00 15360]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 17:43 4670704]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-06-08 20:29 224248]
"PcSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-04-11 17:52 1409024]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-01-27 14:21 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2006-02-10 15:55 15969280 C:\WINDOWS\RTHDCPL.exe]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 15:40 155648]
"GhostStartTrayApp"="C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe" [2002-08-14 15:21 94208]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-06-08 20:29 224248]
"PCSuiteTrayApplication"="C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.exe" [2006-04-26 08:29 237568]
"winload"="C:\Program Files\Internet Explorer\winload.exe" [ ]
"DownloadAccelerator"="C:\Program Files\DAP\DAP.exe" [2000-11-23 08:22 4568576]
"UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" [ ]
"MSDisp32"="C:\WINDOWS\system32\drvmif.dll" [2008-02-11 21:26 15872]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-02-16 22:04 579072]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-02-16 22:04 219136]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-09-21 18:45:43 113664]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 17:35:56 65588]
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2008-01-27 14:21:12 124400]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winwea32]
winwea32.dll 2008-02-11 19:31 24576 C:\WINDOWS\system32\winwea32.dll
R1 GhPciScan;GhostPciScanner;C:\Program Files\Symantec\Norton Ghost 2003\ghpciscan.sys [2002-08-14 15:11]
R3 RMSPPPOE;Log2Space;C:\WINDOWS\system32\DRIVERS\RMSPPPOE.SYS [2002-10-03 00:09]
S0 TfFsMon;TfFsMon;C:\WINDOWS\system32\drivers\TfFsMon.sys []
S0 TfSysMon;TfSysMon;C:\WINDOWS\system32\drivers\TfSysMon.sys []
S2 ThreatFire;ThreatFire;C:\Program Files\ThreatFire\TFService.exe service []
S3 TfNetMon;TfNetMon;C:\WINDOWS\system32\drivers\TfNetMon.sys []
.
Contents of the 'Scheduled Tasks' folder
"2008-01-26 18:30:04 C:\WINDOWS\Tasks\At1.job"
- C:\WINDOWS\system32\XqUe6m23.exe
"2008-01-20 19:30:02 C:\WINDOWS\Tasks\At2.job"
- C:\WINDOWS\system32\XqUe6m23.exe
"2008-01-19 10:36:52 C:\WINDOWS\Tasks\At3.job"
- C:\WINDOWS\system32\XqUe6m23.exe
"2008-01-19 10:36:52 C:\WINDOWS\Tasks\At4.job"
- C:\WINDOWS\system32\XqUe6m23.exe
"2008-01-19 10:36:52 C:\WINDOWS\Tasks\At5.job"
- C:\WINDOWS\system32\XqUe6m23.exe
"2008-01-19 10:36:52 C:\WINDOWS\Tasks\At6.job"
- C:\WINDOWS\system32\XqUe6m23.exe
"2008-01-19 10:36:52 C:\WINDOWS\Tasks\At7.job"
- C:\WINDOWS\system32\XqUe6m23.exe
"2008-01-19 10:36:52 C:\WINDOWS\Tasks\At8.job"
- C:\WINDOWS\system32\XqUe6m23.exe
"2008-02-07 02:30:04 C:\WINDOWS\Tasks\At9.job"
- C:\WINDOWS\system32\XqUe6m23.exe
"2008-02-08 03:30:02 C:\WINDOWS\Tasks\At10.job"
- C:\WINDOWS\system32\XqUe6m23.exe
"2008-02-12 04:30:04 C:\WINDOWS\Tasks\At11.job"
- C:\WINDOWS\system32\XqUe6m23.exe
"2008-02-15 05:30:02 C:\WINDOWS\Tasks\At12.job"
- C:\WINDOWS\system32\XqUe6m23.exe
"2008-02-15 06:30:02 C:\WINDOWS\Tasks\At13.job"
- C:\WINDOWS\system32\XqUe6m23.exe
"2008-02-15 07:30:02 C:\WINDOWS\Tasks\At14.job"
- C:\WINDOWS\system32\XqUe6m23.exe
"2008-02-14 08:30:02 C:\WINDOWS\Tasks\At15.job"
- C:\WINDOWS\system32\XqUe6m23.exe
"2008-02-15 09:30:02 C:\WINDOWS\Tasks\At16.job"
- C:\WINDOWS\system32\XqUe6m23.exe
"2008-02-15 10:30:02 C:\WINDOWS\Tasks\At17.job"
- C:\WINDOWS\system32\XqUe6m23.exe
"2008-02-15 11:30:02 C:\WINDOWS\Tasks\At18.job"
- C:\WINDOWS\system32\XqUe6m23.exe
"2008-02-11 12:30:04 C:\WINDOWS\Tasks\At19.job"
- C:\WINDOWS\system32\XqUe6m23.exe
"2008-02-16 13:30:02 C:\WINDOWS\Tasks\At20.job"
- C:\WINDOWS\system32\XqUe6m23.exe
"2008-02-16 14:30:02 C:\WINDOWS\Tasks\At21.job"
- C:\WINDOWS\system32\XqUe6m23.exe
"2008-02-02 15:30:04 C:\WINDOWS\Tasks\At22.job"
- C:\WINDOWS\system32\XqUe6m23.exe
"2008-02-16 16:30:02 C:\WINDOWS\Tasks\At23.job"
- C:\WINDOWS\system32\XqUe6m23.exe
"2008-01-26 17:30:04 C:\WINDOWS\Tasks\At24.job"
- C:\WINDOWS\system32\XqUe6m23.exe
"2008-01-26 18:30:04 C:\WINDOWS\Tasks\At25.job"
- C:\WINDOWS\system32\62u21P00.exe
"2008-01-23 04:24:22 C:\WINDOWS\Tasks\At26.job"
- C:\WINDOWS\system32\62u21P00.exe
"2008-01-23 04:24:22 C:\WINDOWS\Tasks\At27.job"
- C:\WINDOWS\system32\62u21P00.exe
"2008-01-23 04:24:22 C:\WINDOWS\Tasks\At28.job"
- C:\WINDOWS\system32\62u21P00.exe
"2008-01-23 04:24:22 C:\WINDOWS\Tasks\At29.job"
- C:\WINDOWS\system32\62u21P00.exe
"2008-01-23 04:24:22 C:\WINDOWS\Tasks\At30.job"
- C:\WINDOWS\system32\62u21P00.exe
"2008-01-23 04:24:22 C:\WINDOWS\Tasks\At31.job"
- C:\WINDOWS\system32\62u21P00.exe
"2008-01-23 04:24:22 C:\WINDOWS\Tasks\At32.job"
- C:\WINDOWS\system32\62u21P00.exe
"2008-02-07 02:30:04 C:\WINDOWS\Tasks\At33.job"
- C:\WINDOWS\system32\62u21P00.exe
"2008-02-08 03:30:04 C:\WINDOWS\Tasks\At34.job"
- C:\WINDOWS\system32\62u21P00.exe
"2008-02-12 04:30:04 C:\WINDOWS\Tasks\At35.job"
- C:\WINDOWS\system32\62u21P00.exe
"2008-02-15 05:30:02 C:\WINDOWS\Tasks\At36.job"
- C:\WINDOWS\system32\62u21P00.exe
"2008-02-15 06:30:02 C:\WINDOWS\Tasks\At37.job"
- C:\WINDOWS\system32\62u21P00.exe
"2008-02-15 07:30:02 C:\WINDOWS\Tasks\At38.job"
- C:\WINDOWS\system32\62u21P00.exe
"2008-02-14 08:30:02 C:\WINDOWS\Tasks\At39.job"
- C:\WINDOWS\system32\62u21P00.exe
"2008-02-15 09:30:02 C:\WINDOWS\Tasks\At40.job"
- C:\WINDOWS\system32\62u21P00.exe
"2008-02-15 10:30:02 C:\WINDOWS\Tasks\At41.job"
- C:\WINDOWS\system32\62u21P00.exe
"2008-02-15 11:30:02 C:\WINDOWS\Tasks\At42.job"
- C:\WINDOWS\system32\62u21P00.exe
"2008-02-11 12:30:04 C:\WINDOWS\Tasks\At43.job"
- C:\WINDOWS\system32\62u21P00.exe
"2008-02-16 13:30:02 C:\WINDOWS\Tasks\At44.job"
- C:\WINDOWS\system32\62u21P00.exe
"2008-02-16 14:30:02 C:\WINDOWS\Tasks\At45.job"
- C:\WINDOWS\system32\62u21P00.exe
"2008-02-02 15:30:04 C:\WINDOWS\Tasks\At46.job"
- C:\WINDOWS\system32\62u21P00.exe
"2008-02-16 16:30:02 C:\WINDOWS\Tasks\At47.job"
- C:\WINDOWS\system32\62u21P00.exe
"2008-01-26 17:30:04 C:\WINDOWS\Tasks\At48.job"
- C:\WINDOWS\system32\62u21P00.exe
"2008-02-01 10:47:20 C:\WINDOWS\Tasks\At49.job"
- C:\WINDOWS\system32\Mk80U01j.exe
"2008-02-01 10:47:20 C:\WINDOWS\Tasks\At50.job"
- C:\WINDOWS\system32\Mk80U01j.exe
"2008-02-01 10:47:20 C:\WINDOWS\Tasks\At51.job"
- C:\WINDOWS\system32\Mk80U01j.exe
"2008-02-01 10:47:20 C:\WINDOWS\Tasks\At52.job"
- C:\WINDOWS\system32\Mk80U01j.exe
"2008-02-01 10:47:20 C:\WINDOWS\Tasks\At53.job"
- C:\WINDOWS\system32\Mk80U01j.exe
"2008-02-01 10:47:20 C:\WINDOWS\Tasks\At54.job"
- C:\WINDOWS\system32\Mk80U01j.exe
"2008-02-01 10:47:20 C:\WINDOWS\Tasks\At55.job"
- C:\WINDOWS\system32\Mk80U01j.exe
"2008-02-01 10:47:20 C:\WINDOWS\Tasks\At56.job"
- C:\WINDOWS\system32\Mk80U01j.exe
"2008-02-07 02:30:04 C:\WINDOWS\Tasks\At57.job"
- C:\WINDOWS\system32\Mk80U01j.exe
"2008-02-08 03:30:04 C:\WINDOWS\Tasks\At58.job"
- C:\WINDOWS\system32\Mk80U01j.exe
"2008-02-12 04:30:04 C:\WINDOWS\Tasks\At59.job"
- C:\WINDOWS\system32\Mk80U01j.exe
"2008-02-15 05:30:02 C:\WINDOWS\Tasks\At60.job"
- C:\WINDOWS\system32\Mk80U01j.exe
"2008-02-15 06:30:02 C:\WINDOWS\Tasks\At61.job"
- C:\WINDOWS\system32\Mk80U01j.exe
"2008-02-15 07:30:02 C:\WINDOWS\Tasks\At62.job"
- C:\WINDOWS\system32\Mk80U01j.exe
"2008-02-14 08:30:02 C:\WINDOWS\Tasks\At63.job"
- C:\WINDOWS\system32\Mk80U01j.exe
"2008-02-15 09:30:02 C:\WINDOWS\Tasks\At64.job"
- C:\WINDOWS\system32\Mk80U01j.exe
"2008-02-15 10:30:02 C:\WINDOWS\Tasks\At65.job"
- C:\WINDOWS\system32\Mk80U01j.exe
"2008-02-15 11:30:02 C:\WINDOWS\Tasks\At66.job"
- C:\WINDOWS\system32\Mk80U01j.exe
"2008-02-11 12:30:04 C:\WINDOWS\Tasks\At67.job"
- C:\WINDOWS\system32\Mk80U01j.exe
"2008-02-16 13:30:02 C:\WINDOWS\Tasks\At68.job"
- C:\WINDOWS\system32\Mk80U01j.exe
"2008-02-16 14:30:02 C:\WINDOWS\Tasks\At69.job"
- C:\WINDOWS\system32\Mk80U01j.exe
"2008-02-02 15:30:04 C:\WINDOWS\Tasks\At70.job"
- C:\WINDOWS\system32\Mk80U01j.exe
"2008-02-16 16:30:02 C:\WINDOWS\Tasks\At71.job"
- C:\WINDOWS\system32\Mk80U01j.exe
"2008-02-01 10:47:20 C:\WINDOWS\Tasks\At72.job"
- C:\WINDOWS\system32\Mk80U01j.exe
"2008-02-03 04:49:18 C:\WINDOWS\Tasks\At73.job"
- C:\WINDOWS\system32\LChXf67A.exe
"2008-02-03 04:49:18 C:\WINDOWS\Tasks\At74.job"
- C:\WINDOWS\system32\LChXf67A.exe
"2008-02-03 04:49:18 C:\WINDOWS\Tasks\At75.job"
- C:\WINDOWS\system32\LChXf67A.exe
"2008-02-03 04:49:18 C:\WINDOWS\Tasks\At76.job"
- C:\WINDOWS\system32\LChXf67A.exe
"2008-02-03 04:49:18 C:\WINDOWS\Tasks\At77.job"
- C:\WINDOWS\system32\LChXf67A.exe
"2008-02-03 04:49:18 C:\WINDOWS\Tasks\At78.job"
- C:\WINDOWS\system32\LChXf67A.exe
"2008-02-03 04:49:18 C:\WINDOWS\Tasks\At79.job"
- C:\WINDOWS\system32\LChXf67A.exe
"2008-02-03 04:49:18 C:\WINDOWS\Tasks\At80.job"
- C:\WINDOWS\system32\LChXf67A.exe
"2008-02-07 02:30:04 C:\WINDOWS\Tasks\At81.job"
- C:\WINDOWS\system32\LChXf67A.exe
"2008-02-08 03:30:04 C:\WINDOWS\Tasks\At82.job"
- C:\WINDOWS\system32\LChXf67A.exe
"2008-02-12 04:30:04 C:\WINDOWS\Tasks\At83.job"
- C:\WINDOWS\system32\LChXf67A.exe
"2008-02-15 05:30:02 C:\WINDOWS\Tasks\At84.job"
- C:\WINDOWS\system32\LChXf67A.exe
"2008-02-15 06:30:02 C:\WINDOWS\Tasks\At85.job"
- C:\WINDOWS\system32\LChXf67A.exe
"2008-02-15 07:30:02 C:\WINDOWS\Tasks\At86.job"
- C:\WINDOWS\system32\LChXf67A.exe
"2008-02-14 08:30:02 C:\WINDOWS\Tasks\At87.job"
- C:\WINDOWS\system32\LChXf67A.exe
"2008-02-15 09:30:02 C:\WINDOWS\Tasks\At88.job"
- C:\WINDOWS\system32\LChXf67A.exe
"2008-02-15 10:30:02 C:\WINDOWS\Tasks\At89.job"
- C:\WINDOWS\system32\LChXf67A.exe
"2008-02-15 11:30:02 C:\WINDOWS\Tasks\At90.job"
- C:\WINDOWS\system32\LChXf67A.exe
"2008-02-11 12:30:04 C:\WINDOWS\Tasks\At91.job"
- C:\WINDOWS\system32\LChXf67A.exe
"2008-02-16 13:30:02 C:\WINDOWS\Tasks\At92.job"
- C:\WINDOWS\system32\LChXf67A.exe
"2008-02-16 14:30:02 C:\WINDOWS\Tasks\At93.job"
- C:\WINDOWS\system32\LChXf67A.exe
"2008-02-03 04:49:18 C:\WINDOWS\Tasks\At94.job"
- C:\WINDOWS\system32\LChXf67A.exe
"2008-02-16 16:30:02 C:\WINDOWS\Tasks\At95.job"
- C:\WINDOWS\system32\LChXf67A.exe
"2008-02-03 04:49:18 C:\WINDOWS\Tasks\At96.job"
- C:\WINDOWS\system32\LChXf67A.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-02-16 22:11:35
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\imapi.exe
C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
.
**************************************************************************
.
Completion time: 2008-02-16 22:13:30 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-16 16:43:26