"Robert Mateescu" wrote: Hi there,
Please check this post (skip ATF and MBAM):
https://forum.bullguard.com/forum/8/Help-when-try-to-use-internet-_94417.html.
Moreover, download and run Combofix as follows:
1. Reboot your computer in Safe Mode with Networking by pressing F8 (or F5 on some computers) before Windows starts (before the Windows logo appears) and choosing Safe Mode with Networking from the following screen.
2. Download the Combofix tool from
here.
When finished, it will produce a log for you. The log is automatically saved on C:\ and is named Combofix.txt.
3. Restart in Normal Mode and post the log. Check if the redirects are gone.
As an additional workaround, uninstall SpyBot and disable MBAM's real time scanner(if active). Since you are using XP, run a Defrag and a check disk scan. This should increase your PC's speed slightly.
/cheers!
Okay...
I checked out that post and followed the directions. I then ran Combofix in Safe Mode - interestingly, Combofix asked me to disable Bullguard AV while in Safe Mode, yet I couldn't find any mention of BG in the Task Manager, so I ran it anyway, despite the warnings. SpyBot has now been uninstalled.
Here is the Combofix log:
-----------
ComboFix 12-10-21.01 - erwin 21/10/2012 21:09:58.1.2 - x86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.3.1252.61.1033.18.3070.2669 [GMT 10.5:30]
Running from: c:\documents and settings\erwin\My Documents\Downloads\ComboFix.exe
AV: BullGuard Antivirus *Enabled/Updated* {7A9BB333-8EDF-4FDC-A2A5-1A30FA021913}
FW: BullGuard Firewall *Disabled* {2AEF4CB6-61B5-4E60-AF22-D95E75B63FA1}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\hpeE.dll
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\erwin\Application Data\inst.exe
c:\documents and settings\erwin\WINDOWS
C:\Install.exe
c:\windows\iun6002.exe
c:\windows\system32\URTTemp
c:\windows\system32\URTTemp\fusion.dll
c:\windows\system32\URTTemp\mscoree.dll
c:\windows\system32\URTTemp\mscoree.dll.local
c:\windows\system32\URTTemp\mscorsn.dll
c:\windows\system32\URTTemp\mscorwks.dll
c:\windows\system32\URTTemp\msvcr71.dll
c:\windows\system32\URTTemp\regtlib.exe
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_NPF
-------\Legacy_NVSVC
-------\Service_NVSvc
.
.
((((((((((((((((((((((((( Files Created from 2012-09-21 to 2012-10-21 )))))))))))))))))))))))))))))))
.
.
2012-10-21 10:26 . 2012-10-21 10:26 -------- d-----w- c:\documents and settings\Administrator
2012-10-21 00:30 . 2012-10-21 00:30 -------- d-----w- C:\TDSSKiller_Quarantine
2012-10-19 14:11 . 2012-10-19 14:16 -------- d-----w- c:\program files\SpywareBlaster
2012-10-18 05:49 . 2012-07-03 15:25 28008 ----a-w- c:\windows\system32\nvhdap32.dll
2012-10-18 05:49 . 2012-07-03 15:25 124264 ----a-w- c:\windows\system32\drivers\nvhda32.sys
2012-10-18 05:49 . 2012-07-03 07:37 884072 ----a-w- c:\windows\system32\nvhdagenco3220103.dll
2012-10-18 04:33 . 2012-10-18 04:33 -------- d-----w- C:\temp
2012-10-18 04:32 . 2012-09-23 14:28 888168 ----a-w- c:\windows\system32\nvdispgenco32.dll
2012-10-15 14:41 . 2012-10-15 14:41 -------- d-----w- c:\documents and settings\erwin\Application Data\Malwarebytes
2012-10-15 14:40 . 2012-10-15 14:40 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2012-10-15 14:40 . 2012-10-15 14:41 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-10-15 14:40 . 2012-09-07 06:34 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-10-13 11:28 . 2012-10-13 11:28 -------- d-----w- c:\documents and settings\erwin\Application Data\HD Tune Pro
2012-10-13 11:28 . 2012-10-13 11:28 -------- d-----w- c:\program files\HD Tune Pro
2012-10-13 02:05 . 2012-10-13 02:08 -------- d-----w- C:\Python27
2012-10-13 01:55 . 2012-10-13 01:55 -------- d-----w- c:\program files\MSXML 4.0
2012-10-11 07:43 . 2012-10-11 07:43 -------- d-----w- c:\program files\VideoLAN
2012-10-09 02:42 . 2012-10-09 10:56 -------- d-----w- c:\documents and settings\erwin\Application Data\Notepad++
2012-10-09 02:42 . 2012-10-09 02:42 -------- d-----w- c:\program files\Notepad++
2012-10-04 12:39 . 2011-05-30 13:42 240640 ----a-w- c:\windows\system32\xvidvfw.dll
2012-10-04 12:39 . 2011-05-23 09:52 153088 ----a-w- c:\windows\system32\xvid.ax
2012-10-04 12:39 . 2011-05-23 07:46 645632 ----a-w- c:\windows\system32\xvidcore.dll
2012-10-04 12:39 . 2012-10-04 12:40 -------- d-----w- c:\program files\Xvid
2012-09-28 14:20 . 2012-09-28 14:20 -------- d-----w- c:\documents and settings\erwin\Local Settings\Application Data\backburner
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-10-21 10:59 . 2008-11-04 07:42 16608 ----a-w- c:\windows\gdrv.sys
2012-10-09 06:07 . 2012-04-30 03:50 696760 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-10-09 06:07 . 2011-09-30 10:45 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-09-24 05:02 . 2012-06-16 06:35 477168 ----a-w- c:\windows\system32\npdeployJava1.dll
2012-09-24 05:02 . 2011-03-21 06:52 473072 ----a-w- c:\windows\system32\deployJava1.dll
2012-09-24 03:21 . 2009-01-18 16:30 73728 ----a-w- c:\windows\system32\javacpl.cpl
2012-09-23 14:28 . 2012-08-04 20:02 5947392 ----a-w- c:\windows\system32\nvopencl.dll
2012-09-23 14:28 . 2012-02-24 00:25 1009512 ----a-w- c:\windows\system32\nvdispco32.dll
2012-09-23 14:28 . 2012-02-24 00:25 2578792 ----a-w- c:\windows\system32\nvcuvid.dll
2012-09-23 14:28 . 2012-02-24 00:25 1866088 ----a-w- c:\windows\system32\nvcuvenc.dll
2012-09-23 14:28 . 2012-02-24 00:25 17551360 ----a-w- c:\windows\system32\nvcompiler.dll
2012-09-23 14:28 . 2008-03-11 08:25 7446528 ----a-w- c:\windows\system32\nvcuda.dll
2012-09-23 14:28 . 2008-03-11 08:25 4494208 ----a-w- c:\windows\system32\nv4_disp.dll
2012-09-23 14:28 . 2008-03-11 08:25 2376704 ----a-w- c:\windows\system32\nvapi.dll
2012-09-23 14:28 . 2008-03-11 08:25 19103744 ----a-w- c:\windows\system32\nvoglnt.dll
2012-09-23 14:28 . 2008-03-11 08:25 12557728 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2012-09-23 13:04 . 2008-03-11 08:25 54272 ----a-w- c:\windows\system32\nvwddi.dll
2012-09-23 13:04 . 2008-03-11 08:25 15512424 ----a-w- c:\windows\system32\nvcpl.dll
2012-09-23 13:04 . 2008-03-11 08:25 164200 ----a-w- c:\windows\system32\nvsvc32.exe
2012-09-23 13:04 . 2008-03-11 08:25 143720 ----a-w- c:\windows\system32\nvcolor.exe
2012-09-23 13:04 . 2008-03-11 08:25 108392 ----a-w- c:\windows\system32\nvmctray.dll
2012-08-27 19:12 . 2004-08-04 12:00 832512 ----a-w- c:\windows\system32\wininet.dll
2012-08-27 19:12 . 2004-08-04 12:00 1830912 ----a-w- c:\windows\system32\inetcpl.cpl
2012-08-27 19:12 . 2009-06-26 03:26 78336 ----a-w- c:\windows\system32\ieencode.dll
2012-08-27 19:12 . 2004-08-04 12:00 17408 ----a-w- c:\windows\system32\corpol.dll
2012-08-27 12:46 . 2010-03-18 16:03 100216 ----a-w- c:\windows\system32\BgGamingMonitor.dll
2012-08-24 13:52 . 2004-08-04 12:00 178176 ----a-w- c:\windows\system32\wintrust.dll
2012-08-21 13:33 . 2004-08-04 12:00 2148864 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-08-21 12:58 . 2004-08-03 22:59 2027520 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-08-12 01:15 . 2010-04-19 12:16 54624 ----a-w- c:\windows\system32\BGLsp.dll
2009-11-26 20:23 . 2009-11-26 20:24 774144 ----a-w- c:\program files\RngInterstitial.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Xvid"="c:\program files\Xvid\CheckUpdate.exe" [2011-01-17 8192]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 81920]
"USSShReg"="c:\progra~1\PHOTOI~1\USSSHREG.EXE" [1996-08-18 16896]
"BullGuard"="c:\program files\BullGuard Ltd\BullGuard\BullGuard.exe" [2012-09-11 1756512]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-11 919008]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2012-04-03 446392]
"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS6ServiceManager"="c:\program files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" [2012-03-09 1073312]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2012-09-23 15512424]
"NvMediaCenter"="NvMCTray.dll" [2012-09-23 108392]
"nwiz"="c:\program files\NVIDIA Corporation\nview\nwiz.exe" [2012-09-23 1634112]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-09-17 254896]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\erwin\Start Menu\Programs\Startup\
gest.lnk - c:\program files\GIGABYTE\GEST\gest.exe [2008-11-4 285192]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BsMain]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BsScanner]
@="Service"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\CNAC3RPK.EXE"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Sony Ericsson\\Update Engine\\Sony Ericsson Update Engine.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\fallout new vegas\\FalloutNVLauncher.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\monitor.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\manager.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\server.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\dawn of war ii - retribution\\DOW2.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\fallen earth f2p\\FEUpdater.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\skyrim\\SkyrimLauncher.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\skyrim\\CreationKit.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NVIDIA Update Core\\daemonu.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\Borderlands 2\\Binaries\\Win32\\Launcher.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1064:TCP"= 1064:TCP:Akamai NetSession Interface
"5000:UDP"= 5000:UDP:Akamai NetSession Interface
.
R1 BdSpy;BdSpy;c:\windows\system32\drivers\BdSpy.sys [12/03/2010 8:04 PM 64608]
R1 NovaShieldFilterDriver;NovaShieldFilterDriver;c:\windows\system32\drivers\NSKernel.sys [27/01/2011 5:52 PM 789960]
R1 NovaShieldTDIDriver;NovaShieldTDIDriver;c:\windows\system32\drivers\NSNetmon.sys [27/01/2011 5:52 PM 19272]
R2 BsBackup;BullGuard backup service;c:\windows\System32\SvcHost.exe -k BullGuard_Backup [4/08/2004 10:30 PM 14336]
R2 BsBhvScan;BullGuard Behavioural Detection;c:\program files\BullGuard Ltd\BullGuard\BullGuardBhvScanner.exe [27/01/2011 5:52 PM 321376]
R2 BsFileScan;BullGuard on-access service;c:\windows\System32\SvcHost.exe -k BullGuard [4/08/2004 10:30 PM 14336]
R2 BsFire;BullGuard firewall service;c:\windows\System32\SvcHost.exe -k BullGuard [4/08/2004 10:30 PM 14336]
R2 BsMailProxy;BullGuard e-mail monitoring service;c:\windows\System32\SvcHost.exe -k BullGuard_Proxy [4/08/2004 10:30 PM 14336]
R2 BsMain;BullGuard main service;c:\windows\System32\SvcHost.exe -k BullGuard_Main [4/08/2004 10:30 PM 14336]
R2 BsScanner;BullGuard scanning service;c:\program files\BullGuard Ltd\BullGuard\BullGuardScanner.exe [4/03/2010 6:37 AM 178528]
R2 BsUpdate;BullGuard update service;c:\program files\BullGuard Ltd\BullGuard\BullGuardUpdate.exe [27/08/2012 11:12 PM 304480]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [24/02/2012 10:58 AM 1258856]
R2 Prvflder;Prvflder;c:\windows\system32\drivers\prvflder.sys [21/04/2006 8:22 AM 70912]
R3 afw;Agnitum firewall driver;c:\windows\system32\drivers\Afw.sys [18/09/2008 7:47 PM 32512]
R3 AfwCore;Agnitum Firewall Core Driver;c:\windows\system32\drivers\AfwCore.sys [5/11/2008 12:40 AM 284928]
R3 GEST Service;GEST Service for program management.;c:\program files\GIGABYTE\GEST\GSvr.exe [4/11/2008 6:13 PM 47624]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32.sys [18/10/2012 4:19 PM 124264]
R3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\drivers\seehcri.sys [31/01/2010 9:49 AM 27632]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2/07/2009 6:39 PM 133104]
S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [13/07/2012 2:28 PM 160944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [30/04/2012 2:20 PM 250808]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2/07/2009 6:39 PM 133104]
S3 oflpydin;oflpydin;\??\c:\docume~1\erwin\LOCALS~1\Temp\oflpydin.sys --> c:\docume~1\erwin\LOCALS~1\Temp\oflpydin.sys [?]
S3 pcouffin;VSO Software pcouffin;c:\windows\system32\drivers\pcouffin.sys [17/01/2010 11:59 PM 47360]
S3 qcusbser;Qualcomm USB Device for Legacy Serial Communication;c:\windows\system32\DRIVERS\qcusbser.sys --> c:\windows\system32\DRIVERS\qcusbser.sys [?]
S3 s1018bus;Sony Ericsson Device 1018 driver (WDM);c:\windows\system32\drivers\s1018bus.sys [18/12/2009 9:54 PM 86824]
S3 s1018mdfl;Sony Ericsson Device 1018 USB WMC Modem Filter;c:\windows\system32\drivers\s1018mdfl.sys [18/12/2009 9:54 PM 15016]
S3 s1018mdm;Sony Ericsson Device 1018 USB WMC Modem Driver;c:\windows\system32\drivers\s1018mdm.sys [18/12/2009 9:54 PM 114728]
S3 s1018mgmt;Sony Ericsson Device 1018 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s1018mgmt.sys [18/12/2009 9:54 PM 106208]
S3 s1018nd5;Sony Ericsson Device 1018 USB Ethernet Emulation (NDIS);c:\windows\system32\drivers\s1018nd5.sys [18/12/2009 9:54 PM 26024]
S3 s1018obex;Sony Ericsson Device 1018 USB WMC OBEX Interface;c:\windows\system32\drivers\s1018obex.sys [18/12/2009 9:54 PM 104744]
S3 s1018unic;Sony Ericsson Device 1018 USB Ethernet Emulation (WDM);c:\windows\system32\drivers\s1018unic.sys [18/12/2009 9:54 PM 109864]
S3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion;c:\program files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [12/04/2011 7:39 AM 155344]
S3 SwitchBoard;Adobe SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [19/02/2010 2:37 PM 517096]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
BullGuard_Main REG_MULTI_SZ BsMain
BullGuard REG_MULTI_SZ BsFileScan BsFire
BullGuard_LowPriv REG_MULTI_SZ BsBrowser
Akamai REG_MULTI_SZ Akamai
BullGuard_Backup REG_MULTI_SZ BsBackup
BullGuard_Proxy REG_MULTI_SZ BsMailProxy
.
Contents of the 'Scheduled Tasks' folder
.
2012-10-21 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-30 06:07]
.
2012-10-19 c:\windows\Tasks\AdobeAAMUpdater-1.0-ERWIN01-erwin.job
- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2012-08-13 20:39]
.
2012-10-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-02 08:08]
.
2012-10-21 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-02 08:08]
.
2012-10-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-861567501-838170752-725345543-1004Core.job
- c:\documents and settings\erwin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-03-09 12:36]
.
2012-10-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-861567501-838170752-725345543-1004UA.job
- c:\documents and settings\erwin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-03-09 12:36]
.
2012-10-21 c:\windows\Tasks\ParetoLogic Registration.job
- c:\program files\Common Files\ParetoLogic\UUS2\UUS.dll [2008-02-22 01:55]
.
2012-10-02 c:\windows\Tasks\ParetoLogic Update Version2.job
- c:\program files\Common Files\ParetoLogic\UUS2\Pareto_Update.exe [2008-02-22 01:55]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.au/
IE: Add to Windows &Live Favorites - https://favorites.live.com/quickadd.aspx
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
LSP: c:\windows\system32\BGLsp.dll
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\documents and settings\erwin\Application Data\Mozilla\Firefox\Profiles\5ceh22dq.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1561457&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - TorrentReactor.Net Customized Web Search
FF - prefs.js: browser.startup.homepage - mira.astroempires.com/empire.aspx
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1561457&SearchSource=2&q=
.
- - - - ORPHANS REMOVED - - - -
.
HKCU-Run-AdobeBridge - (no file)
HKLM-Run-GEST - c:\program files\GIGABYTE\GEST\run.exe
SafeBoot-37767017.sys
AddRemove-HeavyMetal_Aero - c:\windows\iun6002.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, https://www.gmer.net
Rootkit scan 2012-10-21 21:28
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-861567501-838170752-725345543-1004\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
[HKEY_USERS\S-1-5-21-861567501-838170752-725345543-1004\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"??"=hex:3d,4e,1c,b8,15,00,97,52,35,1b,1c,88,8a,ef,da,8a,c8,92,c4,95,ff,50,5f,
21,cb,8a,3f,a7,b2,84,83,89,7c,e3,21,ca,d5,0c,45,1a,65,3e,bb,20,e1,1a,08,b6,\
"??"=hex:ec,cd,11,3a,ce,18,98,ac,a2,5b,d2,3d,7d,67,18,6a
.
[HKEY_USERS\S-1-5-21-861567501-838170752-725345543-1004\Software\SecuROM\License information*]
"datasecu"=hex:51,da,43,66,12,df,d8,4d,a5,a6,2d,3b,f4,1b,38,90,3f,47,ce,19,ac,
e9,b5,8a,b9,3b,03,24,70,91,50,0c,31,39,09,a0,90,ef,4e,df,d5,e9,40,14,d4,11,\
"rkeysecu"=hex:98,ea,b1,56,ee,3f,f0,1f,40,83,b4,67,ec,30,dd,9a
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'lsass.exe'(928)
c:\windows\system32\BGLsp.dll
.
- - - - - - - > 'explorer.exe'(2556)
c:\windows\system32\WININET.dll
c:\program files\BullGuard Ltd\BullGuard\spamfilter\LittleHook.dll
c:\program files\NVIDIA Corporation\nview\nview.dll
c:\program files\Microsoft Private Folder 1.0\ShellExt.dll
c:\windows\system32\PFLib.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\msi.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\BullGuard Ltd\BullGuard\BackupShellHook.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Microsoft Private Folder 1.0\PrfldSvc.exe
c:\program files\Google\Update\1.3.21.123\GoogleCrashHandler.exe
c:\windows\system32\CNAC3RPK.EXE
c:\windows\system32\RunDLL32.exe
c:\windows\system32\rundll32.exe
.
**************************************************************************
.
Completion time: 2012-10-21 21:33:46 - machine was rebooted
ComboFix-quarantined-files.txt 2012-10-21 11:03
.
Pre-Run: 140,824,530,944 bytes free
Post-Run: 140,246,953,984 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect /usepmtimer
.
- - End Of File - - 8C6933015060BB269E00CA81ED446A7C