logfile from combofix:
ComboFix 08-02-17.2 - lllll 2008-02-17 17:44:32.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.949.82.1033.18.68 [GMT -5:00]
Running from: C:\Documents and Settings\lllll\Desktop\ComboFix.exe
[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\check_LSA7.txt
C:\Program Files\Temporary
C:\Program Files\WinBudget
C:\Program Files\WinBudget\bin\crap.1191359948.old
C:\Program Files\WinBudget\bin\crap.1192476496.old
C:\Program Files\WinBudget\bin\matrix.dat
C:\WINDOWS\system32\arwrukic.dll
C:\WINDOWS\system32\cbadd.bak1
C:\WINDOWS\system32\cbadd.ini
C:\WINDOWS\system32\efhkj.bak1
C:\WINDOWS\system32\efhkj.bak2
C:\WINDOWS\system32\efhkj.ini
C:\WINDOWS\system32\efhkj.ini2
C:\WINDOWS\system32\efhkj.tmp
C:\WINDOWS\system32\ehkmp.bak1
C:\WINDOWS\system32\ehkmp.ini
C:\WINDOWS\system32\gpvcrmxa.dll
C:\WINDOWS\system32\hjjlm.bak1
C:\WINDOWS\system32\hjjlm.bak2
C:\WINDOWS\system32\hjjlm.ini
C:\WINDOWS\system32\hjkkj.bak1
C:\WINDOWS\system32\hjkkj.ini
C:\WINDOWS\system32\jjjlm.bak1
C:\WINDOWS\system32\jjjlm.ini
C:\WINDOWS\system32\ktuetxuk.dll
C:\WINDOWS\system32\lcthjcjo.dll
C:\WINDOWS\system32\leukblvw.dll
C:\WINDOWS\system32\lmllm.bak1
C:\WINDOWS\system32\lmllm.ini
C:\WINDOWS\system32\lnnmp.bak1
C:\WINDOWS\system32\lnnmp.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\ofjdavau.dll
C:\WINDOWS\system32\orqss.bak1
C:\WINDOWS\system32\orqss.bak2
C:\WINDOWS\system32\orqss.ini
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\pnrfilbt.dll
C:\WINDOWS\system32\prqss.bak1
C:\WINDOWS\system32\prqss.bak2
C:\WINDOWS\system32\prqss.ini
C:\WINDOWS\system32\qqstv.bak1
C:\WINDOWS\system32\qqstv.bak2
C:\WINDOWS\system32\qqstv.ini
C:\WINDOWS\system32\rtstv.bak1
C:\WINDOWS\system32\rtstv.bak2
C:\WINDOWS\system32\rtstv.ini
C:\WINDOWS\system32\rttss.bak1
C:\WINDOWS\system32\rttss.bak2
C:\WINDOWS\system32\rttss.ini
C:\WINDOWS\system32\tstwa.bak1
C:\WINDOWS\system32\tstwa.ini
C:\WINDOWS\system32\tttss.bak1
C:\WINDOWS\system32\tttss.bak2
C:\WINDOWS\system32\tttss.ini
C:\WINDOWS\system32\ttutv.bak1
C:\WINDOWS\system32\urktsvhy.dll
C:\WINDOWS\system32\vybeg.bak1
C:\WINDOWS\system32\vybeg.ini
C:\WINDOWS\system32\wqsuxluy.dll
C:\WINDOWS\system32\xbbwiaqm.dll
C:\WINDOWS\system32\ybeeg.bak1
C:\WINDOWS\system32\ybeeg.ini
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_CMDSERVICE
-------\LEGACY_DOMAINSERVICE
-------\LEGACY_NETWORK_MONITOR
((((((((((((((((((((((((( Files Created from 2008-01-17 to 2008-02-17 )))))))))))))))))))))))))))))))
.
2008-02-17 16:14 . 2008-02-17 16:14 356,352 --a------ C:\WINDOWS\eSellerateEngine.dll
2008-02-17 15:30 . 2008-02-17 15:30 <DIR> d-------- C:\Program Files\MSBuild
2008-02-17 15:19 . 2008-02-17 15:19 <DIR> d-------- C:\WINDOWS\system32\XPSViewer
2008-02-17 15:18 . 2008-02-17 15:18 <DIR> d-------- C:\Program Files\Reference Assemblies
2008-02-17 15:15 . 2006-06-29 13:07 14,048 --------- C:\WINDOWS\system32\spmsg2.dll
2008-02-17 15:04 . 2008-02-17 15:04 <DIR> d-------- C:\WINDOWS\LastGood
2008-02-17 09:55 . 2008-02-17 09:55 <DIR> d-------- C:\Program Files\Audacity
2008-02-16 19:58 . 2008-02-16 19:58 <DIR> d-------- C:\Program Files\Viewpoint
2008-02-16 17:47 . 2008-02-16 19:35 <DIR> d-------- C:\Documents and Settings\lllll\.housecall6.6
2008-02-15 22:04 . 2008-02-16 16:40 1,074 ---hs---- C:\WINDOWS\system32\lmujrxxp.ini
2008-02-15 21:34 . 2008-02-16 17:18 <DIR> d-------- C:\VundoFix Backups
2008-02-15 21:32 . 2008-02-15 22:04 954 ---hs---- C:\WINDOWS\system32\waalgonj.ini
2008-02-15 21:27 . 2008-02-17 08:19 <DIR> d-------- C:\Program Files\7-Zip
2008-02-12 20:44 . 2008-02-15 21:31 834 ---hs---- C:\WINDOWS\system32\htfjmdhg.ini
2008-02-11 16:52 . 2008-02-12 16:52 654 ---hs---- C:\WINDOWS\system32\pctjqxow.ini
2008-02-11 06:59 . 2008-02-11 15:36 534 ---hs---- C:\WINDOWS\system32\leqadwol.ini
2008-02-10 11:18 . 2008-02-11 06:47 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2008-02-10 10:17 . 2008-02-11 06:48 414 ---hs---- C:\WINDOWS\system32\nvgtyepv.ini
2008-02-09 18:07 . 2008-02-09 23:02 1,254 ---hs---- C:\WINDOWS\system32\lieuccfb.ini
2008-02-09 12:16 . 2008-02-09 18:02 1,194 ---hs---- C:\WINDOWS\system32\qbtdsusn.ini
2008-02-08 17:56 . 2008-02-08 17:56 <DIR> d-------- C:\Program Files\InterActual
2008-02-08 16:46 . 2008-02-09 12:10 1,074 ---hs---- C:\WINDOWS\system32\uasrpuqt.ini
2008-02-08 15:13 . 2008-02-08 15:13 894 ---hs---- C:\WINDOWS\system32\kcypkmku.ini
2008-02-07 15:11 . 2008-02-08 15:10 834 ---hs---- C:\WINDOWS\system32\hknamwlk.ini
2008-02-06 15:12 . 2008-02-07 15:02 714 ---hs---- C:\WINDOWS\system32\ururmxnc.ini
2008-02-05 15:04 . 2008-02-06 15:06 594 ---hs---- C:\WINDOWS\system32\xeiqvkxd.ini
2008-02-04 20:20 . 2008-02-05 15:02 414 ---hs---- C:\WINDOWS\system32\illcmmqe.ini
2008-02-03 17:27 . 2008-02-04 20:04 1,314 ---hs---- C:\WINDOWS\system32\cygsivgc.ini
2008-02-02 21:44 . 2008-02-16 17:42 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\HAURI
2008-02-02 09:56 . 2008-02-03 10:10 1,014 --ahs---- C:\WINDOWS\system32\ofvlipmm.ini
2008-02-01 23:14 . 2008-02-02 09:45 774 --ahs---- C:\WINDOWS\system32\fnthbvfo.ini
2008-01-31 23:14 . 2008-02-01 20:54 654 --ahs---- C:\WINDOWS\system32\trxrsohc.ini
2008-01-30 23:17 . 2008-01-31 19:00 474 --ahs---- C:\WINDOWS\system32\lmktdnvm.ini
2008-01-29 22:52 . 2008-01-30 22:52 1,434 --ahs---- C:\WINDOWS\system32\jwmktato.ini
2008-01-29 22:43 . 2008-02-17 14:50 <DIR> d-------- C:\Documents and Settings\Lucy\Programs
2008-01-29 22:35 . 2008-01-29 22:35 <DIR> d-------- C:\spoolerlogs
2008-01-29 14:30 . 2008-01-29 22:47 1,194 --ahs---- C:\WINDOWS\system32\dxsbnarn.ini
2008-01-29 11:09 . 2008-01-29 11:09 1,074 --ahs---- C:\WINDOWS\system32\ssowhjhp.ini
2008-01-28 13:54 . 2008-01-29 11:04 1,014 --ahs---- C:\WINDOWS\system32\uvqwtuxl.ini
2008-01-27 16:13 . 2008-01-28 10:03 774 --ahs---- C:\WINDOWS\system32\opnvnjpi.ini
2008-01-27 10:51 . 2008-01-27 15:59 594 --ahs---- C:\WINDOWS\system32\qdbybrdn.ini
2008-01-26 21:48 . 2008-01-26 21:48 1,158 --a------ C:\WINDOWS\mozver.dat
2008-01-26 16:41 . 2008-01-27 10:43 474 --ahs---- C:\WINDOWS\system32\iejrheag.ini
2008-01-25 20:22 . 2008-01-25 20:22 294 --ahs---- C:\WINDOWS\system32\dysxirbx.ini
2008-01-24 18:53 . 2008-01-24 18:53 294 --ahs---- C:\WINDOWS\system32\oghtrysm.ini
2008-01-23 21:17 . 2008-01-24 16:05 526 --ahs---- C:\WINDOWS\system32\ynmwdyjy.ini
2008-01-23 18:57 . 2008-01-23 18:57 294 --ahs---- C:\WINDOWS\system32\hvjkqlpj.ini
2008-01-22 19:27 . 2008-01-22 19:27 294 --ahs---- C:\WINDOWS\system32\livsjltl.ini
2008-01-21 09:52 . 2008-01-21 09:52 294 --ahs---- C:\WINDOWS\system32\akndxmlk.ini
2008-01-20 10:50 . 2008-01-20 10:50 <DIR> d-------- C:\Program Files\Microsoft.NET
2008-01-20 09:55 . 2008-01-20 09:55 <DIR> d-------- C:\Documents and Settings\lllll\Application Data\Hnc
2008-01-20 09:53 . 2008-01-20 09:53 1,014 --ahs---- C:\WINDOWS\system32\famqlddv.ini
2008-01-19 15:33 . 2008-01-20 08:29 954 --ahs---- C:\WINDOWS\system32\btovqtrh.ini
2008-01-18 17:40 . 2008-01-19 12:16 834 --ahs---- C:\WINDOWS\system32\ddnyfcyh.ini
2008-01-18 06:45 . 2008-01-18 17:40 654 --ahs---- C:\WINDOWS\system32\vaygknju.ini
2008-01-17 16:45 . 2008-01-18 06:01 474 --ahs---- C:\WINDOWS\system32\gulwbqjn.ini
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-17 13:19 --------- d-----w C:\Program Files\Common Files\Motive
2008-02-17 13:19 --------- d-----w C:\Program Files\Common Files\AOL
2008-02-17 02:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL
2008-02-17 02:10 --------- d-----w C:\Program Files\Verizon
2008-02-17 01:00 --------- d-----w C:\Program Files\AIM6
2008-02-17 00:58 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-02-17 00:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL Downloads
2008-02-16 23:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\bak
2008-02-16 02:27 --------- d-----w C:\Documents and Settings\lllll\Application Data\HAURI
2008-02-10 16:23 --------- d-----w C:\Program Files\Common Files\Adobe
2008-01-30 04:18 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-16 04:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kodak
2008-01-05 23:38 --------- d-----w C:\Documents and Settings\lllll\Application Data\Jamdat
2008-01-05 22:56 --------- d-----w C:\Program Files\TryMedia
2007-12-29 02:38 --------- d-----w C:\Program Files\ReflexiveArcade
2007-12-29 00:45 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-08-31 17:39 28,160 ----a-w C:\Documents and Settings\All Users\Application Data\m.exe
2007-08-31 17:31 18,432 --sh--r C:\Documents and Settings\All Users\Application Data\SVCH0ST.EXE
2007-08-31 17:24 125,440 --sh--r C:\Documents and Settings\All Users\Application Data\EXPL0RER.EXE
2007-08-31 17:39 40,960 --sh--w C:\WINDOWS\AFEF4706E4C5.dll
2007-08-31 17:39 65,024 --sh--w C:\WINDOWS\AFEF4706E4C5.exe
2005-07-29 20:24 472 --sha-r C:\WINDOWS\cGM\w3g.vbs
2007-10-11 22:40 6,473 --sha-w C:\WINDOWS\system32\dgjlm.bak1
2007-10-14 14:44 691,044 --sha-w C:\WINDOWS\system32\dgjlm.bak2
2007-10-07 14:35 6,473 --sha-w C:\WINDOWS\system32\nqtss.bak1
2007-10-10 00:26 6,543 --sha-w C:\WINDOWS\system32\nqtss.ini2
2007-10-25 11:00 6,473 --sha-w C:\WINDOWS\system32\onnmp.bak1
2007-11-13 20:02 6,473 --sha-w C:\WINDOWS\system32\onnmp.bak2
2007-10-29 20:06 6,473 --sha-w C:\WINDOWS\system32\qstwa.bak1
2007-10-18 19:10 6,473 --sha-w C:\WINDOWS\system32\rqtwa.bak1
2007-10-24 20:19 419,569 --sha-w C:\WINDOWS\system32\rqtwa.bak2
2007-10-03 15:07 230,912 --sh--r C:\WINDOWS\sеcurity\wоwexec.exe
2007-10-04 20:38 70,144 --sh--r C:\WINDOWS\Мicrosoft\rundll32.exe
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{19D74B48-EDD5-4C95-87B5-7D72C6A083E2}]
C:\WINDOWS\system32\somhppjh.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{26908d47-81d3-4e00-a415-d1e261707774}]
C:\WINDOWS\system32\cklydvik.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3C9EEDAD-80FF-43F0-961C-E0210FF9327A}]
C:\WINDOWS\system32\vtsqq.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{45D27744-EFA7-CC72-F54E-EA2B2EE68C93}]
C:\WINDOWS\system32\slmtmbmk.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9BA04454-5949-49F2-8E0C-EF2F269663D4}]
C:\WINDOWS\system32\jkhfe.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D9F9944F-460D-4546-E5BD-EF20740FEE95}]
C:\Program Files\MSN\lagusijax.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EC45E3FE-C16D-4F24-9238-D1B49AD74815}]
2007-05-15 09:00 135168 --a------ C:\Program Files\HAURI\ViRobot Desktop 5.5\Service\hWebMan.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{f394cb47-68e7-4389-b5eb-5be14c6d024a}]
C:\WINDOWS\system32\yfixhwg.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2007-10-02 16:11 27664]
"Aim6"="" []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Ink Monitor"="C:\Program Files\EPSON\Ink Monitor\InkMonitor.exe" [2007-10-02 16:11 27664]
"HEProtect"="C:\Program Files\HAURI\ViRobot Desktop 5.5\AntiSpam\HSockPE.exe" [2007-01-04 05:00 221184]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-10-02 16:11 27664]
"IeServerhelp"="C:\Documents and Settings\All Users\Application Data\EXPL0RER.EXE" [2007-08-31 12:24 125440]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"c83ce041"="C:\WINDOWS\system32\pxxrjuml.dll" [ ]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
EPSON Status Monitor 3 Environment Check 2.lnk - C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE [2007-08-17 13:30:47 127488]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
"DF"= C:\Documents and Settings\All Users\Favorites\C:\Documents and Settings\All Users\Favorites\C:\Documents and Settings\All Users\Favorites\C:\Documents and Settings\All Users\Favorites\C:\Documents and Settings\All Users\Favorites\GNUFKPIK.exe.exe.exe.exe.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoInstrumentation"= 1 (0x1)
"NoSMHelp"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\[u]0[/u]]
Source= C:\Program Files\MSN\propryhdecowu.html
FriendlyName=
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{1BDBB504-0390-4821-AB7F-F8F38103DAE8}"= C:\WINDOWS\AFEF4706E4C5.dll [2007-08-31 12:39 40960]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-03 23:56 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HncUpdate]
C:\WINDOWS\system32\HncUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
--a------ 2005-09-20 09:32 77824 C:\WINDOWS\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
--a------ 2005-09-20 09:36 114688 C:\WINDOWS\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
--a------ 2005-09-20 09:35 94208 C:\WINDOWS\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\imekrmig7.0]
--a------ 2003-07-14 21:57 19520 C:\Program Files\Common Files\Microsoft Shared\IME\IMKR7\IMEKRMIG.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
--a------ 2004-08-03 21:32 208952 C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 10:50 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
--a------ 2004-08-03 21:32 455168 C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
--a------ 2004-08-03 21:32 455168 C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--a------ 2003-10-31 18:42 32768 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
--a------ 2006-01-11 14:08 577536 C:\WINDOWS\soundman.exe
R2 hpcsvc;ViRobot Communication Service;C:\Program Files\HAURI\ViRobot Desktop 5.5\hpcsvc.exe [2007-06-26 04:00]
R3 VRFWNTD5;VRFWNTD5 Hauri Network Driver;C:\WINDOWS\system32\drivers\VRFWNTD5.sys [2007-04-24 08:00]
R3 VRsecos;VRsecos;C:\WINDOWS\system32\drivers\VRsecos.sys [2007-05-10 10:00]
S2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 16:38]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{beffebc8-b33c-11dc-b266-00155875ca91}]
\Shell\AutoRun\command - F:\ielp.exe
\Shell\explore\Command - F:\ielp.exe
\Shell\open\Command - F:\ielp.exe
*Newly Created Service* - BITS
*Newly Created Service* - CLR_OPTIMIZATION_V2.0.50727_32
*Newly Created Service* - FONTCACHE3.0.0.0
*Newly Created Service* - IDSVC
.
Contents of the 'Scheduled Tasks' folder
"2008-02-15 05:00:00 C:\WINDOWS\Tasks\At1.job"
- C:\WINDOWS\system32\O35PCQI2.exe
"2008-02-17 14:00:02 C:\WINDOWS\Tasks\At10.job"
- C:\WINDOWS\system32\O35PCQI2.exe
"2008-02-17 15:00:00 C:\WINDOWS\Tasks\At11.job"
- C:\WINDOWS\system32\O35PCQI2.exe
"2008-02-17 16:00:03 C:\WINDOWS\Tasks\At12.job"
- C:\WINDOWS\system32\O35PCQI2.exe
"2008-02-17 17:00:01 C:\WINDOWS\Tasks\At13.job"
- C:\WINDOWS\system32\O35PCQI2.exe
"2008-02-17 18:00:00 C:\WINDOWS\Tasks\At14.job"
- C:\WINDOWS\system32\O35PCQI2.exe
"2008-02-17 19:00:01 C:\WINDOWS\Tasks\At15.job"
- C:\WINDOWS\system32\O35PCQI2.exe
"2008-02-17 20:00:00 C:\WINDOWS\Tasks\At16.job"
- C:\WINDOWS\system32\O35PCQI2.exe
"2008-02-17 21:00:01 C:\WINDOWS\Tasks\At17.job"
- C:\WINDOWS\system32\O35PCQI2.exe
"2008-02-17 22:00:03 C:\WINDOWS\Tasks\At18.job"
- C:\WINDOWS\system32\O35PCQI2.exe
"2008-02-16 23:00:07 C:\WINDOWS\Tasks\At19.job"
- C:\WINDOWS\system32\O35PCQI2.exe
"2008-02-15 06:00:00 C:\WINDOWS\Tasks\At2.job"
- C:\WINDOWS\system32\O35PCQI2.exe
"2008-02-17 00:00:00 C:\WINDOWS\Tasks\At20.job"
- C:\WINDOWS\system32\O35PCQI2.exe
"2008-02-17 01:00:00 C:\WINDOWS\Tasks\At21.job"
- C:\WINDOWS\system32\O35PCQI2.exe
"2008-02-17 02:00:01 C:\WINDOWS\Tasks\At22.job"
- C:\WINDOWS\system32\O35PCQI2.exe
"2008-02-17 03:00:00 C:\WINDOWS\Tasks\At23.job"
- C:\WINDOWS\system32\O35PCQI2.exe
"2008-02-17 04:00:00 C:\WINDOWS\Tasks\At24.job"
- C:\WINDOWS\system32\O35PCQI2.exe
"2008-02-15 07:00:00 C:\WINDOWS\Tasks\At3.job"
- C:\WINDOWS\system32\O35PCQI2.exe
"2008-02-15 08:00:00 C:\WINDOWS\Tasks\At4.job"
- C:\WINDOWS\system32\O35PCQI2.exe
"2008-02-15 09:00:00 C:\WINDOWS\Tasks\At5.job"
- C:\WINDOWS\system32\O35PCQI2.exe
"2008-02-15 10:00:00 C:\WINDOWS\Tasks\At6.job"
- C:\WINDOWS\system32\O35PCQI2.exe
"2008-02-15 11:00:00 C:\WINDOWS\Tasks\At7.job"
- C:\WINDOWS\system32\O35PCQI2.exe
"2008-02-11 12:00:00 C:\WINDOWS\Tasks\At8.job"
- C:\WINDOWS\system32\O35PCQI2.exe
"2008-01-19 13:00:00 C:\WINDOWS\Tasks\At9.job"
- C:\WINDOWS\system32\O35PCQI2.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-17 17:47:27
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-02-17 17:48:36
ComboFix-quarantined-files.txt 2008-02-17 22:48:14
awf.txt file:
Find AWF report by noahdfear ?006
Version 1.40
The current date is: 02/17/2008 Sun
The current time is: 17:50:49.59
bak folders found
~~~~~~~~~~~
Directory of C:\PROGRA~1\MESSEN~1\BAK
08/04/2004 00:06 1,667,584 msmsgs.exe
1 File(s) 1,667,584 bytes
Directory of C:\WINDOWS\SYSTEM32\BAK
08/03/2004 23:56 15,360 ctfmon.exe
1 File(s) 15,360 bytes
Directory of C:\DOCUME~1\ALLUSE~1\APPLIC~1\BAK
0 File(s) 0 bytes
Directory of C:\PROGRA~1\EPSON\INKMON~1\BAK
02/16/2008 18:34 258,048 InkMonitor.exe
1 File(s) 258,048 bytes
Directory of C:\PROGRA~1\ADOBE\READER~1.0\READER\BAK
05/11/2007 02:06 40,048 Reader_sl.exe
1 File(s) 40,048 bytes
Directory of C:\PROGRA~1\HAURI\COMMON\BASE\BAK
0 File(s) 0 bytes
Directory of C:\PROGRA~1\HAURI\VIROBO~1.5\ANTISPAM\BAK
0 File(s) 0 bytes
Directory of C:\PROGRA~1\JAVA\JRE16~1.0_0\BIN\BAK
07/12/2007 03:00 132,496 jusched.exe
1 File(s) 132,496 bytes
Duplicate files of bak directory contents
~~~~~~~~~~~~~~~~~~~~~~~
27664 2007-10-02 "C:\Program Files\Messenger\msmsgs.exe"
1667584 2004-08-04 "C:\Program Files\Messenger\bak\msmsgs.exe"
15360 2004-08-03 "C:\WINDOWS\system32\ctfmon.exe"
15360 2004-08-03 "C:\WINDOWS\system32\bak\ctfmon.exe"
27664 2007-10-02 "C:\Program Files\EPSON\Ink Monitor\InkMonitor.exe"
258048 2008-02-16 "C:\Program Files\EPSON\Ink Monitor\bak\InkMonitor.exe"
39792 2008-01-11 "C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe"
40048 2007-05-11 "C:\Program Files\Adobe\Reader 8.0\Reader\bak\Reader_sl.exe"
27664 2007-10-02 "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
132496 2007-07-12 "C:\Program Files\Java\jre1.6.0_02\bin\bak\jusched.exe"
end of report