here is the combofix log
Rochelle - 06-08-21 16:20:40.64
ComboFix 06.08.18 - Running from: C:\Documents and Settings\Rochelle\Desktop
((((((((((((((((((((((((((((((((((((((((((((( Look2Me's Log ))))))))))))))))))))))))))))))))))))))))))))))))))
REGISTRY ENTRIES REMOVED:
[HKEY_CLASSES_ROOT\CLSID\{4D976275-11CB-409E-9D9F-8F94F36E6EC0}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{4D976275-11CB-409E-9D9F-8F94F36E6EC0}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{4D976275-11CB-409E-9D9F-8F94F36E6EC0}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{4D976275-11CB-409E-9D9F-8F94F36E6EC0}\InprocServer32]
@="C:\\WINDOWS\\system32\\mQpistub.dll"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{62D28E14-B732-40B6-86C9-85D1092DDBF2}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{62D28E14-B732-40B6-86C9-85D1092DDBF2}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{62D28E14-B732-40B6-86C9-85D1092DDBF2}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{62D28E14-B732-40B6-86C9-85D1092DDBF2}\InprocServer32]
@="C:\\WINDOWS\\system32\\guard.tmp"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{9D83C593-777B-4A59-84D0-967120D030CC}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{9D83C593-777B-4A59-84D0-967120D030CC}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{9D83C593-777B-4A59-84D0-967120D030CC}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{9D83C593-777B-4A59-84D0-967120D030CC}\InprocServer32]
@="C:\\WINDOWS\\system32\\maexcl40.dll"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{F753C5B3-C30E-4BF2-BF16-7283FE6A7963}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{F753C5B3-C30E-4BF2-BF16-7283FE6A7963}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{F753C5B3-C30E-4BF2-BF16-7283FE6A7963}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{F753C5B3-C30E-4BF2-BF16-7283FE6A7963}\InprocServer32]
@="C:\\WINDOWS\\system32\\mcvcrt20.dll"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{313E3AB1-CBE6-43F6-9790-FA68DFC90423}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{313E3AB1-CBE6-43F6-9790-FA68DFC90423}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{313E3AB1-CBE6-43F6-9790-FA68DFC90423}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{313E3AB1-CBE6-43F6-9790-FA68DFC90423}\InprocServer32]
@="C:\\WINDOWS\\system32\\ksdcr.dll"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{E67263EE-87B8-4498-ADE6-69D8208AD31A}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{E67263EE-87B8-4498-ADE6-69D8208AD31A}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{E67263EE-87B8-4498-ADE6-69D8208AD31A}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{E67263EE-87B8-4498-ADE6-69D8208AD31A}\InprocServer32]
@="C:\\WINDOWS\\system32\\kmdno1.dll"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{7A120583-7EFE-47CA-93E1-FD685DC97C48}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{7A120583-7EFE-47CA-93E1-FD685DC97C48}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{7A120583-7EFE-47CA-93E1-FD685DC97C48}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{7A120583-7EFE-47CA-93E1-FD685DC97C48}\InprocServer32]
@="C:\\WINDOWS\\system32\\kgdsl1.dll"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{8924D3C9-C0BC-49C1-BC55-A28C80B1D5BB}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{8924D3C9-C0BC-49C1-BC55-A28C80B1D5BB}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{8924D3C9-C0BC-49C1-BC55-A28C80B1D5BB}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{8924D3C9-C0BC-49C1-BC55-A28C80B1D5BB}\InprocServer32]
@="C:\\WINDOWS\\system32\\guard.tmp"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{05FAB7A4-2E2D-4C17-8748-5821E4300BE5}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{05FAB7A4-2E2D-4C17-8748-5821E4300BE5}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{05FAB7A4-2E2D-4C17-8748-5821E4300BE5}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{05FAB7A4-2E2D-4C17-8748-5821E4300BE5}\InprocServer32]
@="C:\\WINDOWS\\system32\\dlcprop2.dll"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{6491E3FB-DF22-444E-9819-98D4216F177C}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{6491E3FB-DF22-444E-9819-98D4216F177C}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{6491E3FB-DF22-444E-9819-98D4216F177C}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{6491E3FB-DF22-444E-9819-98D4216F177C}\InprocServer32]
@="C:\\WINDOWS\\system32\\iqsecsvc.dll"
"ThreadingModel"="Apartment"
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
FILES REMOVED:
C:\WINDOWS\system32\cqyptui.dll
C:\WINDOWS\system32\ditmsft.dll
C:\WINDOWS\system32\dlcprop2.dll
C:\WINDOWS\system32\enlol1331.dll
C:\WINDOWS\system32\i4lo0e33eh.dll
C:\WINDOWS\system32\iqsecsvc.dll
C:\WINDOWS\system32\ir42l5ho1.dll
C:\WINDOWS\system32\izdkcs32.dll
C:\WINDOWS\system32\jjproxy.dll
C:\WINDOWS\system32\k644lghq164e.dll
C:\WINDOWS\system32\kgdsl1.dll
C:\WINDOWS\system32\kmdno1.dll
C:\WINDOWS\system32\ktlul7391.dll
C:\WINDOWS\system32\l02slaf71d2.dll
C:\WINDOWS\system32\lv2o09f3e.dll
C:\WINDOWS\system32\lvru0999e.dll
C:\WINDOWS\system32\LYPMONRC.DLL
C:\WINDOWS\system32\maexcl40.dll
C:\WINDOWS\system32\mcvcrt20.dll
C:\WINDOWS\system32\mQpistub.dll
C:\WINDOWS\system32\ojeacc.dll
C:\WINDOWS\system32\ojedlg.dll
C:\WINDOWS\system32\t48u0el9ehq.dll
C:\WINDOWS\system32\vpmredir.dll
C:\WINDOWS\system32\wdwfax.dll
C:\WINDOWS\system32\guard.tmp
C:\WINDOWS\system32\guard.tmp_tobedeleted
Granting sedebugprivilege to Administrators ... successful
((((((((((((((((((((((((((((((((((((((((((( E-Give / Ssk's Log )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\repairs303169590.dll_tobedeleted
C:\Documents and Settings\Anisha\Application Data\Sskknwrd.dll
C:\Documents and Settings\Matthew\Application Data\Sskcwrd.dll
C:\Documents and Settings\Matthew\Application Data\Sskknwrd.dll
C:\Documents and Settings\Rochelle\Application Data\Sskknwrd.dll
C:\WINDOWS\system32\bk.exe
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\keyboard1.dat
C:\WINDOWS\newname.dat
C:\dfndrff_12.exe
C:\kybrdff_12.exe
C:\nwnmff_12.exe
C:\Documents and Settings\Rochelle\Local Settings\Temporary Internet Files\Content.IE5\0PQ7G5MZ\dfndrff_11[1].exe
C:\Documents and Settings\Rochelle\Local Settings\Temporary Internet Files\Content.IE5\0PQ7G5MZ\drsmartload46a[1].exe
C:\Documents and Settings\Rochelle\Local Settings\Temporary Internet Files\Content.IE5\C7U1K50I\drsmartload849a[1].exe
C:\Documents and Settings\Rochelle\Local Settings\Temporary Internet Files\Content.IE5\C7U1K50I\MTE3NDI6ODoxNg[1].exe
C:\Documents and Settings\Rochelle\Local Settings\Temporary Internet Files\Content.IE5\C7U1K50I\nwnmff_11[1].exe
C:\Documents and Settings\Rochelle\Local Settings\Temporary Internet Files\Content.IE5\ICOXY4LN\kybrdff_11[1].exe
C:\Documents and Settings\Rochelle\Local Settings\Temporary Internet Files\Content.IE5\P451CUGP\drsmartload45a[1].exe
C:\Documents and Settings\Rochelle\Local Settings\Temporary Internet Files\Content.IE5\P451CUGP\stub_113_4_0_4_0[1].exe
C:\WINDOWS\system32\bszip.dll
C:\WINDOWS\system32\cmd.com
C:\WINDOWS\system32\netstat.com
C:\WINDOWS\system32\ping.com
C:\WINDOWS\system32\regedit.com
C:\WINDOWS\system32\setup.exe.tmp
C:\WINDOWS\system32\taskkill.com
C:\WINDOWS\system32\tasklist.com
C:\WINDOWS\system32\tracert.com
C:\WINDOWS\system32\tsuninst.exe
C:\WINDOWS\system32\winlog.exe
C:\WINDOWS\uninstall_nmon.vbs
C:\WINDOWS\system32\atmtd.dll
C:\WINDOWS\system32\atmtd.dll._
C:\Documents and Settings\LocalService\Application Data\NetMon
C:\Program Files\Deskbar
C:\Program Files\ToolBar888
C:\Program Files\outlook
C:\Program Files\network monitor
C:\Program Files\Common Files\{603A0ADF-0711-1033-1017-05042805002c}
C:\WINDOWS\VG9ueQ
((((((((((((((((((((((((((((((( Files Created from 2006-07-21 to 2006-08-21 ))))))))))))))))))))))))))))))))))
2006-08-19 15:10 48,190 C:\WINDOWS\RDFX4.exe
2006-08-18 11:26 61,952 C:\WINDOWS\system32\aaa00000.dll
2006-08-18 11:26 1,167 C:\WINDOWS\system32\aaa00000.sys
2006-08-17 19:52 24,296 C:\WINDOWS\icont.exe
2006-08-17 12:42 1,167 C:\WINDOWS\system32\ykg21013.sys
2006-08-17 12:41 61,952 C:\WINDOWS\system32\ykg21013.dll
2006-08-17 12:38 110,592 C:\WINDOWS\v1201.exe
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-08-21 16:25 -------- d-------- C:\Program Files\Common Files
2006-08-21 16:14 -------- d-------- C:\Program Files\Mozilla Firefox
2006-08-20 23:40 -------- d-------- C:\Program Files\Lx_cats
2006-08-20 20:06 1167 --a------ C:\WINDOWS\system32\aaa00000.sys
2006-08-19 15:10 48190 --a------ C:\WINDOWS\RDFX4.exe
2006-08-19 15:10 -------- d-------- C:\Program Files\Windows NT
2006-08-19 15:10 -------- d-------- C:\Program Files\Windows Media Player
2006-08-19 15:10 -------- d-------- C:\Program Files\Messenger
2006-08-18 17:01 -------- d-------- C:\Program Files\Aim Great Two
2006-08-18 11:50 1167 --a------ C:\WINDOWS\system32\ykg21013.sys
2006-08-18 11:26 61952 --a------ C:\WINDOWS\system32\aaa00000.dll
2006-08-18 11:24 -------- d-------- C:\Program Files\Common Files\uufm
2006-08-17 19:52 24296 --a------ C:\WINDOWS\icont.exe
2006-08-17 15:19 -------- d-------- C:\Program Files\Google
2006-08-17 15:10 -------- d---s---- C:\Documents and Settings\Rochelle\Application Data\Microsoft
2006-08-17 12:42 61952 --a------ C:\WINDOWS\system32\ykg21013.dll
2006-08-17 12:38 110592 --a------ C:\WINDOWS\v1201.exe
2006-08-17 12:02 -------- d-------- C:\Documents and Settings\Rochelle\Application Data\Google
2006-08-15 17:07 -------- d-------- C:\Program Files\EA GAMES
2006-08-14 13:02 -------- d-------- C:\Program Files\ModTheSims2.com
2006-08-14 12:45 669002 --a------ C:\WINDOWS\unins000.exe
2006-08-12 21:07 -------- d-------- C:\Program Files\Internet Explorer
2006-07-27 14:24 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
2006-07-21 09:24 72704 --a------ C:\WINDOWS\system32\hlink.dll
2006-07-07 15:24 163644 --a------ C:\WINDOWS\system32\drivers\secdrv.sys
2006-07-07 15:21 -------- d-------- C:\Program Files\Sports Interactive
2006-07-06 23:12 -------- d-------- C:\Program Files\Championship Manager 2006
2006-06-30 13:11 -------- d--h----- C:\Program Files\InstallShield Installation Information
2006-06-14 22:38 1050 --a------ C:\Documents and Settings\Rochelle\Application Data\wklnhst.dat
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"SpeedTouch USB Diagnostics"="\"C:\\Program Files\\Thomson\\SpeedTouch USB\\Dragdiag.exe\" /icon"
"BluetoothAuthenticationAgent"="rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent"
"TPP Auto Loader"="C:\\WINDOWS\\TPPALDR.EXE"
"LXCECATS"="rundll32 C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\LXCEtime.dll,_RunDLLEntry@16"
"lxcemon.exe"="\"C:\\Program Files\\Lexmark 4300 Series\\lxcemon.exe\""
"EzPrint"="\"C:\\Program Files\\Lexmark 4300 Series\\ezprint.exe\""
"FaxCenterServer"="\"C:\\Program Files\\Lexmark Fax Solutions\\fm3032.exe\" /s"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"MessengerPlus3"="\"C:\\Program Files\\MessengerPlus! 3\\MsgPlus.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"ACTX1"="C:\\WINDOWS\\v1201.exe"
"ykg21013"="RUNDLL32.EXE w06980d9.dll,n 003210100000000a06980d9"
"list logo site keep"="C:\\Documents and Settings\\All Users\\Application Data\\global browse list logo\\WarnWipe.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.0.720.3640\\GoogleToolbarNotifier.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="C:\\Program Files\\Windows Media Player\\polobiti.html"
"SubscribedURL"=""
"FriendlyName"=""
"Flags"=dword:00002000
"Position"=hex:2c,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,00,00,e8,\
03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,14,00,00,00,14,00,00,00
"CurrentState"=hex:01,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,\
00,00,01,00,00,00
"RestoredStateInfo"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\1]
"Source"="C:\\Program Files\\Messenger\\meje.html"
"SubscribedURL"=""
"FriendlyName"=""
"Flags"=dword:00002000
"Position"=hex:2c,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,00,00,ea,\
03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,14,00,00,00,14,00,00,00
"CurrentState"=hex:01,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,\
00,00,01,00,00,00
"RestoredStateInfo"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\2]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e2,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,\
00,00,01,00,00,00
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\A8B3E294918498E8.job
C:\WINDOWS\tasks\AD22E9C091819DD4.job
Completion time: 21/08/2006 16:25:10.17
ComboFix.txt