Hi Jack&Jill,
Spybot Teatimer was/is not active, Avira has the closed umbrella in the system tray and I've checked MalwareBytes and Protection is disabled.
I've re-run RogueKiller with option 2 and the report is below.
MBAM updated but still failed to run a scan to completion.
MBAM protection was switched off again and I re-run aswMBR. It still reported the same infection in my earlier entry but this time got as far as starting to scan services before the window closed without completion.
RogueKiller V6.1.0 [09/22/2011] by Tigzy
contact at
http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Feedback:
http://www.sur-la-toile.com/discussion-193725-1-BRogueKillerD-Remontees.html
Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User: RoyK [Admin rights]
Mode: Remove -- Date : 09/23/2011 17:13:04
Bad processes: 3
[SUSP PATH] 2627817058:2645646947.exe -- c:\windows\2627817058:2645646947.exe -> KILLED [TermProc]
[SUSP PATH] vsnphv71.exe -- c:\windows\vsnphv71.exe -> KILLED [TermProc]
[RESIDUE] 2627817058:2645646947.exe -- c:\windows\2627817058:2645646947.exe -> KILLED [TermProc]
Registry Entries: 2
[SUSP PATH] HKLM\[...]\Run : SNPHV71 (C:\WINDOWS\vsnphv71.exe) -> DELETED
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
Particular Files / Folders:
Driver: [LOADED]
SSDT[258] : NtTerminateThread @ 0x80577F1F -> HOOKED (\??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys @ 0xEE4E0E9E)
SSDT[257] : NtTerminateProcess @ 0x805839B9 -> HOOKED (\??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys @ 0xEE4E0E56)
SSDT[254] : NtSuspendThread @ 0x805E05AB -> HOOKED (\??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys @ 0xEE4E0F02)
SSDT[247] : NtSetValueKey @ 0x8057BC5B -> HOOKED (Unknown @ 0xF7CD83E8)
SSDT[224] : NtSetInformationFile @ 0x8057C641 -> HOOKED (\??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys @ 0xEE4E1C40)
SSDT[213] : NtSetContextThread @ 0x8062E33F -> HOOKED (\??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys @ 0xEE4E0F66)
SSDT[204] : NtRestoreKey @ 0x8064FA19 -> HOOKED (Unknown @ 0xF7CD83F7)
SSDT[193] : NtReplaceKey @ 0x8064FE82 -> HOOKED (Unknown @ 0xF7CD83FC)
SSDT[192] : NtRenameKey @ 0x8064F526 -> HOOKED (\??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys @ 0xEE4E52F0)
SSDT[177] : NtQueryValueKey @ 0x8056A419 -> HOOKED (\??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys @ 0xEE4E5386)
SSDT[137] : NtProtectVirtualMemory @ 0x80574E58 -> HOOKED (\??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys @ 0xEE4E1428)
SSDT[128] : NtOpenThread @ 0x8059323B -> HOOKED (Unknown @ 0xF7CD83C5)
SSDT[122] : NtOpenProcess @ 0x80574AA9 -> HOOKED (Unknown @ 0xF7CD83C0)
SSDT[116] : NtOpenFile @ 0x8056F7FF -> HOOKED (\??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys @ 0xEE4E1B2C)
SSDT[98] : NtLoadKey @ 0x805AF5C3 -> HOOKED (Unknown @ 0xF7CD83F2)
SSDT[65] : NtDeleteValueKey @ 0x80595C1A -> HOOKED (Unknown @ 0xF7CD83ED)
SSDT[63] : NtDeleteKey @ 0x80597FFA -> HOOKED (Unknown @ 0xF7CD83E3)
SSDT[62] : NtDeleteFile @ 0x805D7A13 -> HOOKED (\??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys @ 0xEE4E1BD4)
SSDT[53] : NtCreateThread @ 0x80578803 -> HOOKED (Unknown @ 0xF7CD83D4)
SSDT[41] : NtCreateKey @ 0x8057376F -> HOOKED (Unknown @ 0xF7CD83DE)
SSDT[37] : NtCreateFile @ 0x8056F864 -> HOOKED (\??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys @ 0xEE4E1A56)
SSDT[19] : NtAssignProcessToJobObject @ 0x805A2C27 -> HOOKED (\??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys @ 0xEE4E0FC0)
S_SSDT[483] : Unknown -> HOOKED (\??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys @ 0xEE4E1F74)
S_SSDT[477] : Unknown -> HOOKED (\??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys @ 0xEE4E77E2)
S_SSDT[378] : Unknown -> HOOKED (\??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys @ 0xEE4E2000)
S_SSDT[298] : Unknown -> HOOKED (\??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys @ 0xEE4E776A)
S_SSDT[292] : Unknown -> HOOKED (\??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys @ 0xEE4E7686)
S_SSDT[237] : Unknown -> HOOKED (\??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys @ 0xEE4E772E)
S_SSDT[227] : Unknown -> HOOKED (\??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys @ 0xEE4E76E0)
S_SSDT[191] : Unknown -> HOOKED (\??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys @ 0xEE4E7654)
S_SSDT[13] : Unknown -> HOOKED (\??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys @ 0xEE4E7606)
S_SSDT[7] : Unknown -> HOOKED (\??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys @ 0xEE4E77A6)
HOSTS File:
127.0.0.1
www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1
www.008k.com
127.0.0.1 008k.com
127.0.0.1
www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1
www.032439.com
127.0.0.1 032439.com
127.0.0.1
www.0scan.com
127.0.0.1 0scan.com
127.0.0.1
www.1000gratisproben.com
127.0.0.1 1000gratisproben.com
127.0.0.1
www.1001namen.com
127.0.0.1 1001namen.com
127.0.0.1 100888290cs.com
127.0.0.1
www.100888290cs.com
127.0.0.1 100sexlinks.com
127.0.0.1
www.100sexlinks.com
[...]
Finished : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt
Regards
Roy