Combofix:
ComboFix 08-01-20.1 - HP_Owner 2008-01-20 23:04:01.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1981 [GMT 10:00]
Running from: C:\Documents and Settings\HP_Owner\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\HP_Owner\Desktop\CFScript.txt
* Created a new restore point
FILE
C:\WINDOWS\LMI189.tmp
C:\WINDOWS\LMI1C.tmp
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\VundoFix Backups
.
((((((((((((((((((((((((( Files Created from 2007-12-20 to 2008-01-20 )))))))))))))))))))))))))))))))
.
2008-01-18 13:48 . 2008-01-20 13:57 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-01-18 13:48 . 2008-01-20 13:57 1,409 --a------ C:\WINDOWS\QTFont.for
2008-01-16 03:26 . 2008-01-16 03:59 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-01-16 03:26 . 2008-01-16 03:26 <DIR> d-------- C:\Documents and Settings\HP_Owner\Application Data\SUPERAntiSpyware.com
2008-01-16 03:26 . 2008-01-16 03:26 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-01-16 02:26 . 2008-01-20 12:54 <DIR> d-------- C:\WINDOWS\LMI1C.tmp
2008-01-16 01:47 . 2008-01-20 12:54 <DIR> d-------- C:\WINDOWS\LMI189.tmp
2008-01-15 11:20 . 2008-01-15 11:20 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-14 05:40 . 2008-01-14 05:40 <DIR> d-------- C:\nup
2008-01-14 04:33 . 2008-01-14 05:28 <DIR> d-------- C:\Program Files\EsetOnlineScanner
2008-01-13 02:54 . 2008-01-13 02:54 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-01-13 02:54 . 2008-01-13 02:54 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-01-13 02:15 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-11 04:14 . 2008-01-11 04:14 7,168 --ahs---- C:\WINDOWS\Thumbs.db
2008-01-11 04:11 . 2008-01-11 04:11 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-01-11 04:04 . 2008-01-11 04:04 <DIR> d-------- C:\Program Files\Bonjour
2008-01-11 03:49 . 2008-01-11 03:49 <DIR> d-------- C:\Program Files\Common Files\Macrovision Shared
2008-01-11 03:40 . 2008-01-12 11:58 <DIR> d-------- C:\Program Files\PowerISO
2008-01-10 03:39 . 2008-01-10 03:39 <DIR> d-------- C:\Program Files\uTorrent
2008-01-10 03:39 . 2008-01-10 17:19 <DIR> d-------- C:\Documents and Settings\HP_Owner\Application Data\uTorrent
2008-01-09 04:05 . 2008-01-09 04:05 <DIR> d-------- C:\Program Files\Common Files\Adobe Systems Shared
2008-01-09 00:07 . 2008-01-09 00:07 <DIR> d-------- C:\Program Files\Microsoft ActiveSync
2008-01-09 00:07 . 2008-01-09 00:07 376 --a------ C:\WINDOWS\ODBC.INI
2008-01-09 00:06 . 2008-01-09 00:06 <DIR> d-------- C:\WINDOWS\ShellNew
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-20 13:01 --------- d-----w C:\Documents and Settings\HP_Owner\Application Data\Skype
2008-01-20 03:57 --------- d-----w C:\Program Files\iTunes
2008-01-20 02:59 --------- d-----w C:\Documents and Settings\HP_Owner\Application Data\Xfire
2008-01-16 23:08 --------- d-----w C:\Documents and Settings\HP_Owner\Application Data\AVG7
2008-01-15 17:25 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-01-10 18:14 --------- d-----w C:\Program Files\DivX
2008-01-10 18:14 --------- d-----w C:\Program Files\Combined Community Codec Pack
2008-01-10 18:04 --------- d-----w C:\Program Files\Common Files\Adobe
2008-01-09 06:47 --------- d-----w C:\Program Files\World of Warcraft
2008-01-08 18:25 --------- d-----w C:\Program Files\QuickTime
2008-01-08 14:03 --------- d-----w C:\Program Files\Xfire
2007-11-27 23:34 --------- d-----w C:\Program Files\Soulseek
2007-11-27 13:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\InterVideo
2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\system32\lsasrv.dll
2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-27 07:39 230,912 ----a-w C:\WINDOWS\system32\wmasf.dll
2007-10-26 11:16 7,680 ----a-w C:\WINDOWS\system32\ff_vfw.dll
2007-10-21 17:39 267,272 ----a-w C:\WINDOWS\system32\xactengine2_10.dll
2007-10-21 17:37 17,928 ----a-w C:\WINDOWS\system32\X3DAudio1_2.dll
.
((((((((((((((((((((((((((((( snapshot_2008-01-20_12.57.14.18 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-20 02:32:50 237,568 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
+ 2008-01-20 13:03:56 237,568 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
- 2008-01-20 02:32:50 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
+ 2008-01-20 13:03:56 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
- 2008-01-20 02:32:50 237,568 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
+ 2008-01-20 13:03:56 237,568 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
- 2008-01-20 02:32:50 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
+ 2008-01-20 13:03:56 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
- 2008-01-20 02:32:50 3,006,464 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
+ 2008-01-20 13:03:56 3,006,464 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
- 2008-01-20 02:32:50 172,032 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
+ 2008-01-20 13:03:57 172,032 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
- 2008-01-18 03:48:13 102,400 ----a-r C:\WINDOWS\Installer\{B045B608-4A47-4C77-9EAD-06C394503306}\iTunesIco.exe
+ 2008-01-20 03:57:41 102,400 ----a-r C:\WINDOWS\Installer\{B045B608-4A47-4C77-9EAD-06C394503306}\iTunesIco.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06 1318912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-05 05:00 208952]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [ ]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-05 05:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-05 05:00 455168]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [ ]
"SoundMan"="SOUNDMAN.EXE" [2004-07-01 18:58 73728 C:\WINDOWS\SOUNDMAN.EXE]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [ ]
"AlcWzrd"="ALCWZRD.EXE" [2004-07-06 01:05 2550272 C:\WINDOWS\ALCWZRD.EXE]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [ ]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-09-26 14:42 267064]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-10-25 09:58 219136]
C:\Documents and Settings\HP_Owner\Start Menu\Programs\Startup\
Xfire.lnk - C:\Program Files\Xfire\xfire.exe [2007-12-05 12:25:52 2858832]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-05-29 05:31:38 241664]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04 83360]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
R3 Cap7134;ASUS TV7134 WDM Video Capture;C:\WINDOWS\system32\DRIVERS\Cap7134.sys [2004-06-23 20:34]
R3 PhTVTune;ASUS WDM TV Tuner;C:\WINDOWS\system32\DRIVERS\PhTVTune.sys [2004-05-27 18:49]
.
Contents of the 'Scheduled Tasks' folder
"2008-01-18 23:17:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-20 23:08:05
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-20 23:08:57
ComboFix-quarantined-files.txt 2008-01-20 13:08:55
ComboFix2.txt 2008-01-20 02:57:46
ComboFix3.txt 2008-01-12 16:48:19
.
2008-01-15 16:34:41 --- E O F ---
ComboFix 08-01-20.1 - HP_Owner 2008-01-20 23:04:01.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1981 [GMT 10:00]
Running from: C:\Documents and Settings\HP_Owner\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\HP_Owner\Desktop\CFScript.txt
* Created a new restore point
FILE
C:\WINDOWS\LMI189.tmp
C:\WINDOWS\LMI1C.tmp
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\VundoFix Backups
.
((((((((((((((((((((((((( Files Created from 2007-12-20 to 2008-01-20 )))))))))))))))))))))))))))))))
.
2008-01-18 13:48 . 2008-01-20 13:57 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-01-18 13:48 . 2008-01-20 13:57 1,409 --a------ C:\WINDOWS\QTFont.for
2008-01-16 03:26 . 2008-01-16 03:59 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-01-16 03:26 . 2008-01-16 03:26 <DIR> d-------- C:\Documents and Settings\HP_Owner\Application Data\SUPERAntiSpyware.com
2008-01-16 03:26 . 2008-01-16 03:26 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-01-16 02:26 . 2008-01-20 12:54 <DIR> d-------- C:\WINDOWS\LMI1C.tmp
2008-01-16 01:47 . 2008-01-20 12:54 <DIR> d-------- C:\WINDOWS\LMI189.tmp
2008-01-15 11:20 . 2008-01-15 11:20 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-14 05:40 . 2008-01-14 05:40 <DIR> d-------- C:\nup
2008-01-14 04:33 . 2008-01-14 05:28 <DIR> d-------- C:\Program Files\EsetOnlineScanner
2008-01-13 02:54 . 2008-01-13 02:54 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-01-13 02:54 . 2008-01-13 02:54 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-01-13 02:15 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-11 04:14 . 2008-01-11 04:14 7,168 --ahs---- C:\WINDOWS\Thumbs.db
2008-01-11 04:11 . 2008-01-11 04:11 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-01-11 04:04 . 2008-01-11 04:04 <DIR> d-------- C:\Program Files\Bonjour
2008-01-11 03:49 . 2008-01-11 03:49 <DIR> d-------- C:\Program Files\Common Files\Macrovision Shared
2008-01-11 03:40 . 2008-01-12 11:58 <DIR> d-------- C:\Program Files\PowerISO
2008-01-10 03:39 . 2008-01-10 03:39 <DIR> d-------- C:\Program Files\uTorrent
2008-01-10 03:39 . 2008-01-10 17:19 <DIR> d-------- C:\Documents and Settings\HP_Owner\Application Data\uTorrent
2008-01-09 04:05 . 2008-01-09 04:05 <DIR> d-------- C:\Program Files\Common Files\Adobe Systems Shared
2008-01-09 00:07 . 2008-01-09 00:07 <DIR> d-------- C:\Program Files\Microsoft ActiveSync
2008-01-09 00:07 . 2008-01-09 00:07 376 --a------ C:\WINDOWS\ODBC.INI
2008-01-09 00:06 . 2008-01-09 00:06 <DIR> d-------- C:\WINDOWS\ShellNew
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-20 13:01 --------- d-----w C:\Documents and Settings\HP_Owner\Application Data\Skype
2008-01-20 03:57 --------- d-----w C:\Program Files\iTunes
2008-01-20 02:59 --------- d-----w C:\Documents and Settings\HP_Owner\Application Data\Xfire
2008-01-16 23:08 --------- d-----w C:\Documents and Settings\HP_Owner\Application Data\AVG7
2008-01-15 17:25 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-01-10 18:14 --------- d-----w C:\Program Files\DivX
2008-01-10 18:14 --------- d-----w C:\Program Files\Combined Community Codec Pack
2008-01-10 18:04 --------- d-----w C:\Program Files\Common Files\Adobe
2008-01-09 06:47 --------- d-----w C:\Program Files\World of Warcraft
2008-01-08 18:25 --------- d-----w C:\Program Files\QuickTime
2008-01-08 14:03 --------- d-----w C:\Program Files\Xfire
2007-11-27 23:34 --------- d-----w C:\Program Files\Soulseek
2007-11-27 13:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\InterVideo
2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\system32\lsasrv.dll
2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-27 07:39 230,912 ----a-w C:\WINDOWS\system32\wmasf.dll
2007-10-26 11:16 7,680 ----a-w C:\WINDOWS\system32\ff_vfw.dll
2007-10-21 17:39 267,272 ----a-w C:\WINDOWS\system32\xactengine2_10.dll
2007-10-21 17:37 17,928 ----a-w C:\WINDOWS\system32\X3DAudio1_2.dll
.
((((((((((((((((((((((((((((( snapshot_2008-01-20_12.57.14.18 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-20 02:32:50 237,568 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
+ 2008-01-20 13:03:56 237,568 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
- 2008-01-20 02:32:50 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
+ 2008-01-20 13:03:56 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
- 2008-01-20 02:32:50 237,568 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
+ 2008-01-20 13:03:56 237,568 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
- 2008-01-20 02:32:50 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
+ 2008-01-20 13:03:56 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
- 2008-01-20 02:32:50 3,006,464 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
+ 2008-01-20 13:03:56 3,006,464 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
- 2008-01-20 02:32:50 172,032 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
+ 2008-01-20 13:03:57 172,032 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
- 2008-01-18 03:48:13 102,400 ----a-r C:\WINDOWS\Installer\{B045B608-4A47-4C77-9EAD-06C394503306}\iTunesIco.exe
+ 2008-01-20 03:57:41 102,400 ----a-r C:\WINDOWS\Installer\{B045B608-4A47-4C77-9EAD-06C394503306}\iTunesIco.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06 1318912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-05 05:00 208952]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [ ]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-05 05:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-05 05:00 455168]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [ ]
"SoundMan"="SOUNDMAN.EXE" [2004-07-01 18:58 73728 C:\WINDOWS\SOUNDMAN.EXE]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [ ]
"AlcWzrd"="ALCWZRD.EXE" [2004-07-06 01:05 2550272 C:\WINDOWS\ALCWZRD.EXE]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [ ]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-09-26 14:42 267064]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-10-25 09:58 219136]
C:\Documents and Settings\HP_Owner\Start Menu\Programs\Startup\
Xfire.lnk - C:\Program Files\Xfire\xfire.exe [2007-12-05 12:25:52 2858832]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-05-29 05:31:38 241664]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04 83360]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
R3 Cap7134;ASUS TV7134 WDM Video Capture;C:\WINDOWS\system32\DRIVERS\Cap7134.sys [2004-06-23 20:34]
R3 PhTVTune;ASUS WDM TV Tuner;C:\WINDOWS\system32\DRIVERS\PhTVTune.sys [2004-05-27 18:49]
.
Contents of the 'Scheduled Tasks' folder
"2008-01-18 23:17:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-20 23:08:05
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-20 23:08:57
ComboFix-quarantined-files.txt 2008-01-20 13:08:55
ComboFix2.txt 2008-01-20 02:57:46
ComboFix3.txt 2008-01-12 16:48:19
.
2008-01-15 16:34:41 --- E O F ---