Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.446.211 [GMT -5:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Administrator\Desktop\CFScript.txt
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\ConduitEngine
c:\program files\ConduitEngine\appContextMenu.xml
c:\program files\ConduitEngine\ConduitEngine.dll
c:\program files\ConduitEngine\ConduitEngineHelper.exe
c:\program files\ConduitEngine\engineContextMenu.xml
c:\program files\ConduitEngine\EngineSettings.json
c:\program files\ConduitEngine\toolbar.cfg
c:\program files\Software_Master
c:\program files\Software_Master\GottenAppsContextMenu.xml
c:\program files\Software_Master\OtherAppsContextMenu.xml
c:\program files\Software_Master\prxtbSoft.dll
c:\program files\Software_Master\SharedAppsContextMenu.xml
c:\program files\Software_Master\Software_MasterToolbarHelper.exe
c:\program files\Software_Master\tbSoft.dll
c:\program files\Software_Master\toolbar.cfg
c:\program files\Software_Master\ToolbarContextMenu.xml
c:\program files\Software_Master\uninstall.exe
.
--------------- FCopy ---------------
c:\windows\system32\dllcache\tcpip.sys --> c:\windows\system32\drivers\tcpip.sys
c:\windows\system32\dllcache\sfcfiles.dll --> c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((( Files Created from 2011-01-18 to 2011-02-18 )))))))))))))))))))))))))))))))
.
2011-02-18 04:18 . 2008-04-14 10:42 1614848 -c----w- c:\windows\system32\dllcache\sfcfiles.dll
2011-02-18 04:18 . 2008-04-14 05:50 361344 -c----w- c:\windows\system32\dllcache\tcpip.sys
2011-02-18 04:14 . 2011-02-18 04:14 -------- d-----w- C:\SP3
2011-02-17 23:32 . 2011-02-17 23:34 -------- d-----w- c:\documents and settings\Administrator\Application Data\U3
2011-02-17 23:31 . 2001-08-17 18:48 12160 -c--a-w- c:\windows\system32\dllcache\mouhid.sys
2011-02-17 23:31 . 2001-08-17 18:48 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2011-01-25 01:47 . 2011-01-25 01:47 -------- d-----w- c:\documents and settings\Administrator\Application Data\simppulltoolbar
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-14 14:35 . 2010-12-14 14:35 564632 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\tmpidcrl.dll
2010-12-14 14:35 . 2009-08-18 15:30 564632 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\wlidui.dll
2010-12-14 14:35 . 2009-08-18 15:24 17816 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2010-11-23 22:55 . 2010-11-23 22:55 0 ----a-w- c:\windows\system32\ConduitEngine.tmp
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Weather"="c:\program files\AWS\WeatherBug\Weather.exe" [2010-04-29 1652736]
"DW6"="c:\program files\The Weather Channel FW\Desktop\DesktopWeather.exe" [2010-04-16 818288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-05-09 7311360]
"nwiz"="nwiz.exe" [2006-05-09 1519616]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-05-09 86016]
"RTHDCPL"="RTHDCPL.EXE" [2006-07-21 16261632]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2010-04-29 437584]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Java\\jre6\\launch4j-tmp\\wowd.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:Remote Desktop
"65533:TCP"= 65533:TCP:Services
"52344:TCP"= 52344:TCP:Services
"9701:TCP"= 9701:TCP:Services
"9702:TCP"= 9702:TCP:Services
"7489:TCP"= 7489:TCP:Services
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2/2/2010 4:55 PM 304464]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2/2/2010 4:55 PM 20952]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [5/29/2010 7:29 PM 136176]
.
Contents of the 'Scheduled Tasks' folder
2011-02-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-30 00:29]
2011-02-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-30 00:29]
2011-02-18 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2010-02-04 20:50]
2011-02-17 c:\windows\Tasks\User_Feed_Synchronization-{D92E767C-5AAF-4F8D-995A-EAB1906AA541}.job
- c:\windows\system32\msfeedssync.exe [2008-04-14 06:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/?ilc=1
.
- - - - ORPHANS REMOVED - - - -
AddRemove-Software_Master Toolbar - c:\progra~1\SOFTWA~1\UNINST~1.EXE
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-02-18 02:42
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
c:\windows\system32\Ireland: The Emerald Isle.scr 960031 bytes executable
scan completed successfully
hidden files: 1
**************************************************************************
.
Completion time: 2011-02-18 02:43:56
ComboFix-quarantined-files.txt 2011-02-18 07:43
ComboFix2.txt 2011-02-18 04:30
ComboFix3.txt 2011-02-18 00:30
Pre-Run: 149,494,165,504 bytes free
Post-Run: 149,471,805,440 bytes free
- - End Of File - - E6A8F763F77B3F474BC40A35873C8272