Here it is
ComboFix 08-01-04.1 - Amy 2008-01-05 22:50:21.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.118 [GMT -5:00]Running from: C:\Documents and Settings\Amy\Local Settings\Temporary Internet Files\Content.IE5\WQP020TC\ComboFix[1].exe
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2007-12-06 to 2008-01-06 )))))))))))))))))))))))))))))))
.
2008-01-05 22:48 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-05 17:43 . 2008-01-05 17:43 <DIR> d-------- C:\Program Files\MySpace
2008-01-05 17:43 . 2008-01-05 17:43 <DIR> d-------- C:\Documents and Settings\Amy\Application Data\MySpace
2008-01-05 13:29 . 2008-01-05 13:31 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-01-05 13:29 . 2008-01-05 13:29 <DIR> d-------- C:\Documents and Settings\Amy\Application Data\SUPERAntiSpyware.com
2008-01-05 13:29 . 2008-01-05 13:29 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-01-05 12:33 . 2008-01-05 12:33 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-05 12:20 . 2008-01-05 12:24 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SecTaskMan
2008-01-05 12:19 . 2008-01-05 12:24 <DIR> d-------- C:\Program Files\Security Task Manager
2008-01-04 15:27 . 2008-01-04 15:30 <DIR> d-------- C:\Program Files\Rock Tour
2008-01-03 16:56 . 2008-01-03 17:00 80 --a------ C:\WINDOWS\hodjpodj.ini
2008-01-03 16:53 . 2008-01-03 16:55 <DIR> d-------- C:\HODJPODJ
2007-12-24 12:58 . 2007-12-24 12:58 0 --ah----- C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_C oinstaller_Critical.Wdf
2007-12-24 12:58 . 2007-12-24 12:58 0 --ah----- C:\WINDOWS\system32\drivers\Msft_Kernel_zumbus_010 05.Wdf
2007-12-24 12:57 . 2007-12-24 12:57 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-12-24 12:56 . 2007-12-24 13:01 <DIR> d-------- C:\Program Files\Zune
2007-12-20 21:31 . 2007-12-20 21:36 741 --a------ C:\WINDOWS\eReg.dat
2007-12-20 21:30 . 2007-12-20 21:30 <DIR> d-------- C:\Program Files\Electronic Arts
2007-12-20 21:30 . 1999-04-02 16:37 33,792 -ra------ C:\WINDOWS\NPSExec.exe
2007-12-20 21:28 . 2007-12-20 21:28 <DIR> d-------- C:\Program Files\Maxis
2007-12-20 21:27 . 2007-12-20 21:27 <DIR> d-------- C:\Documents and Settings\Amy\WINDOWS
2007-12-20 21:27 . 1998-10-29 17:45 306,688 --a------ C:\WINDOWS\IsUninst.exe
2007-12-06 19:36 . 2007-07-12 02:22 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2008-01-05 19:13 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-05 19:13 --------- d-----w C:\Program Files\CyberLink
2008-01-05 18:29 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-12-09 18:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\shockwave.com
2007-12-07 01:08 --------- d-----w C:\Documents and Settings\Amy\Application Data\LimeWire
2007-12-07 00:37 --------- d-----w C:\Program Files\LimeWire
2007-12-07 00:36 --------- d-----w C:\Program Files\Java
2007-12-02 23:21 --------- d-----w C:\Program Files\Alwil Software
2007-12-02 17:12 --------- d-----w C:\Documents and Settings\Amy\Application Data\Move Networks
2007-12-01 01:35 --------- d-----w C:\Program Files\shockwave.com
2007-11-30 22:19 17,144 ----a-w C:\Documents and Settings\Amy\Application Data\GDIPFONTCACHEV1.DAT
2007-11-29 03:08 --------- d-----w C:\Program Files\Audacity
2007-11-22 21:13 --------- d-----w C:\Documents and Settings\Amy\Application Data\Jasc
2007-11-22 14:34 --------- d-----w C:\Program Files\MSXML 6.0
2007-11-22 02:21 --------- d-----w C:\Program Files\MSECACHE
2007-11-22 02:07 --------- d-----w C:\Program Files\Jasc Software Inc
2007-11-22 02:04 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-11-16 02:51 80,288 ----a-w C:\WINDOWS\system32\ZuneIpTransport.dll
2007-11-16 02:51 72,608 ----a-w C:\WINDOWS\system32\ZuneUsbTransport.dll
2007-11-16 02:51 59,296 ----a-w C:\WINDOWS\system32\ZuneBusEnum.exe
2007-11-16 02:51 45,472 ----a-w C:\WINDOWS\system32\ZuneUsbConnection.dll
2007-11-16 02:51 245,664 ----a-w C:\WINDOWS\system32\ZuneWlanCfgSvc.exe
2007-11-16 02:51 155,552 ----a-w C:\WINDOWS\system32\ZuneMTPZ.dll
2007-11-16 02:38 40,832 ----a-w C:\WINDOWS\system32\drivers\zumbus.sys
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-11 15:00 --------- d-----w C:\Program Files\Ahead
2007-11-11 14:57 --------- d-----w C:\Program Files\Viewpoint
2007-11-11 14:57 --------- d-----w C:\Documents and Settings\Amy\Application Data\Viewpoint
2007-11-11 14:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2007-11-11 14:16 --------- d-----w C:\Program Files\yWriter2
2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-27 22:40 222,720 ----a-w C:\WINDOWS\system32\wmasf.dll
2007-10-18 18:09 1,419,232 ----a-w C:\WINDOWS\system32\WdfCoInstaller01005.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24 1694208]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:00 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe" [2007-07-30 21:47 68856]
"Aim6"="" []
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06 1318912]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-12-18 20:47 8720384]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"NvCplDaemon"="NvQTwk" []
"nwiz"="nwiz.exe" [2002-04-19 13:13 364544 C:\WINDOWS\system32\nwiz.exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00 132496]
"Zune Launcher"="c:\Program Files\Zune\ZuneLauncher.exe" [2007-11-15 21:51 166304]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-12-18 20:47 8720384]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
D-Link AirPlus G Wireless Utility.lnk - C:\Program Files\D-Link\AirPlus G Wireless Adapter Utility\AirPlus.exe [2007-04-30 17:18:28]
D-Link REG Utility.lnk - C:\Program Files\D-Link\AirPlus G Wireless Adapter Utility\Reg.exe [2007-04-30 17:18:28]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 00:01:04]
[hkey_local_machine\software\microsoft\windows\curr entversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
R2 zumbus;Zune Bus Enumerator Driver;C:\WINDOWS\system32\DRIVERS\zumbus.sys [2007-11-15 21:38]
R2 ZuneBusEnum;Zune Bus Enumerator;c:\WINDOWS\system32\ZuneBusEnum.exe [2007-11-15 21:51]
S3 ZuneWlanCfgSvc;Zune Wireless Configuration Service;c:\WINDOWS\system32\ZuneWlanCfgSvc.exe [2007-11-15 21:51]
*Newly Created Service* - PROCEXP90
*Newly Created Service* - SASDIFSV
*Newly Created Service* - SASENUM
*Newly Created Service* - SASKUTIL
.
************************************************** ************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-05 22:55:11
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
Completion time: 2008-01-05 22:56:22
.
2007-12-13 04:37:32 --- E O F ---