:Processes Explorer.EXE :OTL SRV - [2009-03-21 15:08:59 | 00,168,032 | RHS- | M] () [Auto | Stopped] – C:\WINDOWS\system32\jtehm.dll – (csuejix) O4 - HKLM…\Run: [KernelFaultCheck] File not found O33 - MountPoints2{0cc85106-e252-11de-9df0-00ff01000001}\Shell\AutoRun\command - “” = g12g.exe O33 - MountPoints2{0cc85106-e252-11de-9df0-00ff01000001}\Shell\open\Command - “” = g12g.exe NetSvcs: csuejix - C:\WINDOWS\system32\jtehm.dll () [2009-12-25 10:00:00 | 00,000,368 | ---- | M] () – C:\WINDOWS\tasks\At11.job [2009-12-25 09:00:00 | 00,000,368 | ---- | M] () – C:\WINDOWS\tasks\At10.job [2009-12-25 08:00:00 | 00,000,368 | ---- | M] () – C:\WINDOWS\tasks\At9.job [2009-12-25 07:00:00 | 00,000,368 | ---- | M] () – C:\WINDOWS\tasks\At8.job [2009-12-25 06:00:00 | 00,000,368 | ---- | M] () – C:\WINDOWS\tasks\At7.job [2009-12-25 05:00:00 | 00,000,368 | ---- | M] () – C:\WINDOWS\tasks\At6.job [2009-12-25 04:00:00 | 00,000,368 | ---- | M] () – C:\WINDOWS\tasks\At5.job [2009-12-25 03:00:00 | 00,000,368 | ---- | M] () – C:\WINDOWS\tasks\At4.job [2009-12-24 22:00:01 | 00,000,368 | ---- | M] () – C:\WINDOWS\tasks\At23.job [2009-12-24 21:00:00 | 00,000,368 | ---- | M] () – C:\WINDOWS\tasks\At22.job [2009-12-24 20:00:00 | 00,000,368 | ---- | M] () – C:\WINDOWS\tasks\At21.job [2009-12-24 19:00:00 | 00,000,368 | ---- | M] () – C:\WINDOWS\tasks\At20.job [2009-12-24 18:00:01 | 00,000,368 | ---- | M] () – C:\WINDOWS\tasks\At19.job [2009-12-24 17:00:00 | 00,000,368 | ---- | M] () – C:\WINDOWS\tasks\At18.job [2009-12-24 16:00:00 | 00,000,368 | ---- | M] () – C:\WINDOWS\tasks\At17.job [2009-12-24 15:00:00 | 00,000,368 | ---- | M] () – C:\WINDOWS\tasks\At16.job [2009-12-24 14:00:00 | 00,000,368 | ---- | M] () – C:\WINDOWS\tasks\At15.job [2009-12-24 13:00:00 | 00,000,368 | ---- | M] () – C:\WINDOWS\tasks\At14.job [2009-12-24 02:00:00 | 00,000,368 | ---- | M] () – C:\WINDOWS\tasks\At3.job [2009-12-24 01:00:00 | 00,000,368 | ---- | M] () – C:\WINDOWS\tasks\At2.job [2009-12-24 00:02:00 | 00,000,368 | ---- | M] () – C:\WINDOWS\tasks\At1.job 2009-11-29 14:28:52 | 00,000,368 | ---- | C] () – C:\WINDOWS\tasks\At24.job [2009-11-29 14:28:52 | 00,000,368 | ---- | C] () – C:\WINDOWS\tasks\At23.job [2009-11-29 14:28:52 | 00,000,368 | ---- | C] () – C:\WINDOWS\tasks\At22.job [2009-11-29 14:28:52 | 00,000,368 | ---- | C] () – C:\WINDOWS\tasks\At21.job [2009-11-29 14:28:52 | 00,000,368 | ---- | C] () – C:\WINDOWS\tasks\At20.job [2009-11-29 14:28:52 | 00,000,368 | ---- | C] () – C:\WINDOWS\tasks\At19.job [2009-11-29 14:28:52 | 00,000,368 | ---- | C] () – C:\WINDOWS\tasks\At18.job [2009-11-29 14:28:52 | 00,000,368 | ---- | C] () – C:\WINDOWS\tasks\At17.job [2009-11-29 14:28:51 | 00,000,368 | ---- | C] () – C:\WINDOWS\tasks\At9.job [2009-11-29 14:28:51 | 00,000,368 | ---- | C] () – C:\WINDOWS\tasks\At8.job [2009-11-29 14:28:51 | 00,000,368 | ---- | C] () – C:\WINDOWS\tasks\At7.job [2009-11-29 14:28:51 | 00,000,368 | ---- | C] () – C:\WINDOWS\tasks\At6.job [2009-11-29 14:28:51 | 00,000,368 | ---- | C] () – C:\WINDOWS\tasks\At5.job [2009-11-29 14:28:51 | 00,000,368 | ---- | C] () – C:\WINDOWS\tasks\At4.job [2009-11-29 14:28:51 | 00,000,368 | ---- | C] () – C:\WINDOWS\tasks\At3.job [2009-11-29 14:28:51 | 00,000,368 | ---- | C] () – C:\WINDOWS\tasks\At2.job [2009-11-29 14:28:51 | 00,000,368 | ---- | C] () – C:\WINDOWS\tasks\At16.job [2009-11-29 14:28:51 | 00,000,368 | ---- | C] () – C:\WINDOWS\tasks\At15.job [2009-11-29 14:28:51 | 00,000,368 | ---- | C] () – C:\WINDOWS\tasks\At14.job [2009-11-29 14:28:51 | 00,000,368 | ---- | C] () – C:\WINDOWS\tasks\At13.job [2009-11-29 14:28:51 | 00,000,368 | ---- | C] () – C:\WINDOWS\tasks\At12.job [2009-11-29 14:28:51 | 00,000,368 | ---- | C] () – C:\WINDOWS\tasks\At11.job [2009-11-29 14:28:51 | 00,000,368 | ---- | C] () – C:\WINDOWS\tasks\At10.job [2009-11-29 14:28:51 | 00,000,368 | ---- | C] () – C:\WINDOWS\tasks\At1.job [2004-08-04 13:00:00 | 00,168,032 | RHS- | C] () – C:\WINDOWS\System32\jtehm.dll :Files C:\WINDOWS\System32\jtehm.dll :Services csuejix :Reg [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2] :Commands [emptytemp] [Reboot]