Here's the GMER info.
GMER 1.0.15.15641 -
http://www.gmer.net
Rootkit scan 2011-12-16 11:42:53
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 SAMSUNG_HM160HC rev.LQ100-10
Running: inkf83lc.exe; Driver: C:\DOCUME~1\user\LOCALS~1\Temp\pxtdapow.sys
---- Kernel code sections - GMER 1.0.15 ----
.text C:\WINDOWS\System32\DRIVERS\ati2mtag.sys section is writeable [0xF6EB2000, 0x1C5D38, 0xE8000020]
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
---- EOF - GMER 1.0.15 ----
Here's Mini toolkit
MiniToolBox by Farbar
Ran by user (administrator) on 16-12-2011 at 10:24:30
Microsoft Windows XP Home Edition Service Pack 3 (X86)
***************************************************************************
========================= IE Proxy Settings: ==============================
Proxy is not enabled.
No Proxy Server is set.
========================= FF Proxy Settings: ==============================
"network.proxy.type", 4
========================= Hosts content: =================================
94.63.240.163 www.google.com
94.63.240.164 www.bing.com
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
127.0.0.1 www.0scan.com
127.0.0.1 0scan.com
127.0.0.1 1000gratisproben.com
127.0.0.1 www.1000gratisproben.com
127.0.0.1 1001namen.com
127.0.0.1 www.1001namen.com
127.0.0.1 100888290cs.com
127.0.0.1 www.100888290cs.com
127.0.0.1 www.100sexlinks.com
There are 15107 more lines starting with "127.0.0.1"
========================= IP Configuration: ================================
Marvell Yukon 88E8036 PCI-E Fast Ethernet Controller = Local Area Connection (Disconnected)
Broadcom 802.11g Network Adapter = Wireless Network Connection 2 (Connected)
1394 Net Adapter = 1394 Connection 2 (Connected)
# ----------------------------------
# Interface IP Configuration
# ----------------------------------
pushd interface ip
# Interface IP Configuration for "Wireless Network Connection 2"
set address name="Wireless Network Connection 2" source=dhcp
set dns name="Wireless Network Connection 2" source=dhcp register=PRIMARY
set wins name="Wireless Network Connection 2" source=dhcp
popd
# End of interface IP configuration
Windows IP Configuration
Host Name . . . . . . . . . . . . : OGRE1
Primary Dns Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Unknown
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
Ethernet adapter Wireless Network Connection 2:
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Broadcom 802.11g Network Adapter
Physical Address. . . . . . . . . : 00-14-A5-8C-2C-07
Dhcp Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
IP Address. . . . . . . . . . . . : 192.168.0.15
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.0.1
DHCP Server . . . . . . . . . . . : 192.168.0.1
DNS Servers . . . . . . . . . . . : 209.18.47.61
209.18.47.62
Lease Obtained. . . . . . . . . . : Friday, December 16, 2011 10:12:55 AM
Lease Expires . . . . . . . . . . : Friday, December 16, 2011 11:12:55 AM
Server: dns-cac-lb-01.rr.com
Address: 209.18.47.61
Name: google.com
Addresses: 74.125.115.147, 74.125.115.99, 74.125.115.103, 74.125.115.104
74.125.115.105, 74.125.115.106
Pinging google.com [74.125.113.104] with 32 bytes of data:
Reply from 74.125.113.104: bytes=32 time=51ms TTL=50
Reply from 74.125.113.104: bytes=32 time=55ms TTL=50
Ping statistics for 74.125.113.104:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 51ms, Maximum = 55ms, Average = 53ms
Server: dns-cac-lb-01.rr.com
Address: 209.18.47.61
Name: yahoo.com
Addresses: 209.191.122.70, 72.30.2.43, 98.137.149.56, 98.139.180.149
Pinging yahoo.com [72.30.2.43] with 32 bytes of data:
Reply from 72.30.2.43: bytes=32 time=76ms TTL=54
Reply from 72.30.2.43: bytes=32 time=79ms TTL=54
Ping statistics for 72.30.2.43:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 76ms, Maximum = 79ms, Average = 77ms
Server: dns-cac-lb-01.rr.com
Address: 209.18.47.61
Name: bleepingcomputer.com
Address: 208.43.87.2
Pinging bleepingcomputer.com [208.43.87.2] with 32 bytes of data:
Reply from 208.43.87.2: Destination host unreachable.
Reply from 208.43.87.2: Destination host unreachable.
Ping statistics for 208.43.87.2:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 0ms, Maximum = 0ms, Average = 0ms
Pinging 127.0.0.1 with 32 bytes of data:
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
Ping statistics for 127.0.0.1:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 0ms, Maximum = 0ms, Average = 0ms
===========================================================================
Interface List
0x1 ........................... MS TCP Loopback interface
0x2 ...00 14 a5 8c 2c 07 ...... Broadcom 802.11g Network Adapter - Packet Scheduler Miniport
===========================================================================
===========================================================================
Active Routes:
Network Destination Netmask Gateway Interface Metric
0.0.0.0 0.0.0.0 192.168.0.1 192.168.0.15 25
127.0.0.0 255.0.0.0 127.0.0.1 127.0.0.1 1
192.168.0.0 255.255.255.0 192.168.0.15 192.168.0.15 25
192.168.0.15 255.255.255.255 127.0.0.1 127.0.0.1 25
192.168.0.255 255.255.255.255 192.168.0.15 192.168.0.15 25
224.0.0.0 240.0.0.0 192.168.0.15 192.168.0.15 25
255.255.255.255 255.255.255.255 192.168.0.15 192.168.0.15 1
Default Gateway: 192.168.0.1
===========================================================================
Persistent Routes:
None
========================= Winsock entries =====================================
Catalog5 01 C:\Windows\System32\mswsock.dll [245248] (Microsoft Corporation)
Catalog5 02 C:\Windows\System32\winrnr.dll [16896] (Microsoft Corporation)
Catalog5 03 C:\Windows\System32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 01 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 02 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 03 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 04 C:\Windows\system32\rsvpsp.dll [92672] (Microsoft Corporation)
Catalog9 05 C:\Windows\system32\rsvpsp.dll [92672] (Microsoft Corporation)
Catalog9 06 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 07 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 08 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 09 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 10 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 11 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 12 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 13 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 14 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 15 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 16 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 17 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 18 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 19 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 20 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 21 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
========================= Event log errors: ===============================
Application errors:
==================
Error: (12/15/2011 10:34:05 AM) (Source: Microsoft Office 14) (User: )
Description: EventType office11shipassert, P1 NIL, P2 NIL, P3 NIL, P4 NIL, P5 NIL, P6 NIL, P7 NIL, P8 NIL, P9 office11shipassert0, P10 office11shipassert1.
Error: (12/12/2011 07:48:40 PM) (Source: Application Hang) (User: )
Description: Hanging application firefox.exe, version 8.0.0.4325, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Error: (12/09/2011 09:36:33 PM) (Source: LoadPerf) (User: )
Description: Installing the performance counter strings for service WmiApRpl (%2) failed. The
Error code is the first DWORD in Data section.
Error: (12/09/2011 09:36:33 PM) (Source: LoadPerf) (User: )
Description: Unable to update the performance counter strings of the 009 language ID.
The Win32 status returned by the call is the first DWORD in Data section.
Error: (12/09/2011 09:35:35 PM) (Source: LoadPerf) (User: )
Description: Installing the performance counter strings for service WmiApRpl (%2) failed. The
Error code is the first DWORD in Data section.
Error: (12/09/2011 09:35:35 PM) (Source: LoadPerf) (User: )
Description: Unable to update the performance counter strings of the 009 language ID.
The Win32 status returned by the call is the first DWORD in Data section.
Error: (12/09/2011 08:41:13 PM) (Source: LoadPerf) (User: )
Description: Installing the performance counter strings for service WmiApRpl (%2) failed. The
Error code is the first DWORD in Data section.
Error: (12/09/2011 08:41:13 PM) (Source: LoadPerf) (User: )
Description: Unable to update the performance counter strings of the 009 language ID.
The Win32 status returned by the call is the first DWORD in Data section.
Error: (12/09/2011 07:37:24 PM) (Source: LoadPerf) (User: )
Description: Installing the performance counter strings for service WmiApRpl (%2) failed. The
Error code is the first DWORD in Data section.
Error: (12/09/2011 07:37:24 PM) (Source: LoadPerf) (User: )
Description: Unable to update the performance counter strings of the 009 language ID.
The Win32 status returned by the call is the first DWORD in Data section.
System errors:
=============
Error: (12/16/2011 10:10:56 AM) (Source: DCOM) (User: SYSTEM)
Description: DCOM got error "%%1084" attempting to start the service EventSystem with arguments ""
in order to run the server:
{1BE1F766-5536-11D1-B726-00C04FB926AF}
Error: (12/16/2011 03:54:02 AM) (Source: Service Control Manager) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
AmdK8
Fips
Error: (12/16/2011 03:52:49 AM) (Source: DCOM) (User: SYSTEM)
Description: DCOM got error "%%1084" attempting to start the service EventSystem with arguments ""
in order to run the server:
{1BE1F766-5536-11D1-B726-00C04FB926AF}
Error: (12/15/2011 10:04:10 AM) (Source: 0) (User: )
Description: 0xC0000001HarddiskVolume1
Error: (12/15/2011 08:17:47 AM) (Source: Service Control Manager) (User: )
Description: The Speed Disk service service terminated unexpectedly. It has done this 1 time(s).
Error: (12/14/2011 06:30:37 PM) (Source: Dhcp) (User: )
Description: Your computer was not assigned an address from the network (by the DHCP
Server) for the Network Card with network address 0014A58C2C07. The following error
occurred:
%%1223.
Your computer will continue to try and obtain an address on its own from
the network address (DHCP) server.
Error: (12/14/2011 06:30:27 PM) (Source: Dhcp) (User: )
Description: Your computer has lost the lease to its IP address 192.168.0.15 on the
Network Card with network address 0014A58C2C07.
Error: (12/11/2011 04:33:32 AM) (Source: Dhcp) (User: )
Description: Your computer was not assigned an address from the network (by the DHCP
Server) for the Network Card with network address 0014A58C2C07. The following error
occurred:
%%1223.
Your computer will continue to try and obtain an address on its own from
the network address (DHCP) server.
Error: (12/11/2011 04:33:24 AM) (Source: Dhcp) (User: )
Description: Your computer has lost the lease to its IP address 192.168.0.15 on the
Network Card with network address 0014A58C2C07.
Error: (12/09/2011 10:04:28 PM) (Source: DCOM) (User: SYSTEM)
Description: DCOM got error "%%1084" attempting to start the service EventSystem with arguments ""
in order to run the server:
{1BE1F766-5536-11D1-B726-00C04FB926AF}
Microsoft Office Sessions:
=========================
Error: (12/15/2011 10:34:05 AM) (Source: Microsoft Office 14)(User: )
Description: office11shipassertNILNILNILNILNILNILNILNILNILNIL
Error: (12/12/2011 07:48:40 PM) (Source: Application Hang)(User: )
Description: firefox.exe8.0.0.4325hungapp0.0.0.000000000
Error: (12/09/2011 09:36:33 PM) (Source: LoadPerf)(User: )
Description: WmiApRpl
Error: (12/09/2011 09:36:33 PM) (Source: LoadPerf)(User: )
Description: 009
Error: (12/09/2011 09:35:35 PM) (Source: LoadPerf)(User: )
Description: WmiApRpl
Error: (12/09/2011 09:35:35 PM) (Source: LoadPerf)(User: )
Description: 009
Error: (12/09/2011 08:41:13 PM) (Source: LoadPerf)(User: )
Description: WmiApRpl
Error: (12/09/2011 08:41:13 PM) (Source: LoadPerf)(User: )
Description: 009
Error: (12/09/2011 07:37:24 PM) (Source: LoadPerf)(User: )
Description: WmiApRpl
Error: (12/09/2011 07:37:24 PM) (Source: LoadPerf)(User: )
Description: 009
=========================== Installed Programs ============================
µTorrent (Version: 2.2.0)
32 Bit HP CIO Components Installer (Version: 7.1.8)
3GP to MP3 Converter
Adobe AIR (Version: 2.5.1.17730)
Adobe Flash Player 10 ActiveX (Version: 10.2.152.32)
Adobe Flash Player 10 Plugin (Version: 10.3.181.26)
Adobe Reader X (10.1.1) (Version: 10.1.1)
Adobe Shockwave Player 11.5 (Version: 11.5.9.620)
AIM 7
Athlon 64 Processor Driver (Version: 1.1.0.14)
ATI Display Driver (Version: 8.593.100-100210a-095952E-ATI)
BroadCam Video Streaming Server
Broadcom 802.11 Network Adapter (Version: 4.100.15.5)
BufferChm (Version: 140.0.212.000)
Conduit Engine (Version: )
Conexant AC-Link Audio
Connection Keep Alive (Version: 1.0.0)
Coupon Printer for Windows (Version: 5.0.0.0)
D2600 (Version: 140.0.690.000)
DeviceDiscovery (Version: 140.0.212.000)
DJ_SF_05_D2600_Software_Min (Version: 140.0.690.000)
Dungeons & Dragons Online ®: Eberron Unlimited ™ v01.13.01.801 (Version: 01.13.01.8017)
Express Rip
FrostWire 4.21.8 (Version: 4.21.8.0)
GPBaseService2 (Version: 140.0.211.000)
Hero Lab 3.8a (Version: 3.8a)
HijackThis 2.0.2 (Version: 2.0.2)
HP Customer Participation Program 14.0 (Version: 14.0)
HP Deskjet D2600 Printer Driver Software 14.0 Rel. 5 (Version: 14.0)
HP Imaging Device Functions 14.0 (Version: 14.0)
HP Photo Creations (Version: 1.0.0.2024)
HP Smart Web Printing 4.60 (Version: 4.60)
HP Solution Center 14.0 (Version: 14.0)
HP Update (Version: 5.003.001.001)
HPDiagnosticAlert (Version: 1.00.0000)
HPProductAssistant (Version: 140.0.212.000)
HPSSupply (Version: 140.0.211.000)
Java 2 Runtime Environment, SE v1.4.2 (Version: 1.4.2)
Java Auto Updater (Version: 2.0.3.1)
Java 6 Update 24 (Version: 6.0.240)
LiveUpdate (Symantec Corporation) (Version: 3.4.1.238)
Malwarebytes' Anti-Malware
MarketResearch (Version: 140.0.212.000)
MediaFireDownloader
Microsoft .NET Framework 1.1 (Version: 1.1.4322)
Microsoft .NET Framework 1.1 Security Update (KB2572067)
Microsoft .NET Framework 2.0 Service Pack 2 (Version: 2.2.30729)
Microsoft .NET Framework 3.0 Service Pack 2 (Version: 3.2.30729)
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729)
Microsoft Compression Client Pack 1.0 for Windows XP (Version: 1)
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office Access MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Access Setup Metadata MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Excel MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Groove MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office InfoPath MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office OneNote MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Outlook MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office PowerPoint MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Professional Plus 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (French) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (Spanish) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proofing (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Publisher MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Shared MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Shared Setup Metadata MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Word MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Silverlight (Version: 4.0.60831.0)
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.59193)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)
Mozilla Firefox 7.0 (x86 en-US) (Version: 7.0)
MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0)
Nero 7 Ultra Edition (Version: 7.03.0993)
neroxml (Version: 1.0.0)
Norton Cleanup (Version: 12.0.0.52)
Norton PartitionMagic (Version: 8.05.000)
Norton PartitionMagic 8.0 (Version: 8.05.000)
Norton SystemWorks (Symantec Corporation) (Version: 12.0.0.52)
Norton SystemWorks Basic Edition (Version: 12.0.0.52)
Norton Utilities (Version: 12.0.0.52)
Pixillion Image Converter
Realtek AC'97 Audio
RegistryFix v7.1
ScummVM 1.3.1
Shop for HP Supplies (Version: 14.0)
SmartWebPrinting (Version: 140.0.186.000)
Soft Data Fax Modem with SmartCP
SolutionCenter (Version: 140.0.213.000)
Spybot - Search & Destroy (Version: 1.6.2)
Star Wars Galactic Battlegrounds: Saga
Status (Version: 140.0.212.000)
The Game Of Life
Toolbox (Version: 140.0.428.000)
TrayApp (Version: 140.0.212.000)
Trojan Killer 2.1
uTorrentBar Toolbar (Version: 6.2.7.3)
VLC media player 1.1.10 (Version: 1.1.10)
WebFldrs XP (Version: 9.50.6513)
WebReg (Version: 140.0.212.017)
WinAce Archiver (Version: 2.69)
Winamp (Version: 5.621 )
Window Washer
Windows Genuine Advantage Validation Tool (KB892130)
Windows Genuine Advantage Validation Tool (KB892130) (Version: 1.7.0069.2)
Windows Internet Explorer 8 (Version: 20090308.140743)
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Service Pack 3 (Version: 20080414.031525)
========================= Memory info: ===================================
Percentage of memory in use: 49%
Total physical RAM: 958.23 MB
Available physical RAM: 483.49 MB
Total Pagefile: 1929.41 MB
Available Pagefile: 1578.55 MB
Total Virtual: 2047.88 MB
Available Virtual: 1973.05 MB
========================= Partitions: =====================================
1 Drive c: () (Fixed) (Total:149.03 GB) (Free:74.08 GB) NTFS
========================= Users: ========================================
User accounts for \\OGRE1
Administrator ASPNET Guest
HelpAssistant SUPPORT_388945a0 user
**** End of log ****
MBAM log
12/16/2011 11:52:32 AM
mbam-log-2011-12-16 (11-52-32).txt
Scan type: Quick scan
Objects scanned: 174319
Time elapsed: 4 minute(s), 16 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\documents and settings\user\Desktop\eXplorer.exe (Heuristics.Reserved.Word.Exploit) -> Not selected for removal. ---This is actually RDKiller