Results redirected -- logs now attached
Thanks for the guidance. I have now followed the 8 (or 7) steps and now paste the files below as specified.
Malware Bytes [Note this is the most recent log. When I first ran this it found various Malware, which I then quartintied and deleted. If you need this file, I have a copy.
Code:
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4090
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
12/05/2010 20:27:23
mbam-log-2010-05-12 (20-27-23).txt
Scan type: Quick scan
Objects scanned: 152766
Time elapsed: 1 hour(s), 25 minute(s), 9 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
File 2: GMER Log
Code:
MER 1.0.15.15281 - [url]http://www.gmer.net[/url]
Rootkit scan 2010-05-13 09:35:49
Windows 5.1.2600 Service Pack 3
Running: uvgp0260.exe; Driver: C:\DOCUME~1\Dad\LOCALS~1\Temp\pxdoypod.sys
---- Kernel code sections - GMER 1.0.15 ----
.rsrc C:\WINDOWS\system32\drivers\ABP480N5.SYS entry point in ".rsrc" section [0xF7754594]
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\system32\svchost.exe[580] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 0099000A
.text C:\WINDOWS\system32\svchost.exe[580] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 009A000A
.text C:\WINDOWS\system32\svchost.exe[580] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 0098000C
.text C:\WINDOWS\Explorer.EXE[912] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00B6000A
.text C:\WINDOWS\Explorer.EXE[912] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00C0000A
.text C:\WINDOWS\Explorer.EXE[912] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00B5000C
---- Devices - GMER 1.0.15 ----
Device -> \Driver\atapi \Device\Harddisk0\DR0 8A8A9EE4
---- Registry - GMER 1.0.15 ----
Reg HKLM\SOFTWARE\Classes\CLSID\{254CCE58-C94E-22D6-6CB9-D3AE9DAF86F2}\InprocServer32@ C:\WINDOWS\system32\quartz.dll
Reg HKLM\SOFTWARE\Classes\CLSID\{254CCE58-C94E-22D6-6CB9-D3AE9DAF86F2}\InprocServer32@ThreadingModel Both
---- Files - GMER 1.0.15 ----
File C:\WINDOWS\system32\drivers\ABP480N5.SYS suspicious modification
File C:\WINDOWS\system32\drivers\atapi.sys suspicious modification
---- EOF - GMER 1.0.15 ----
File 3 DDS is attached (too big to paste here)
File 4 - attach.txt -- is attached
Hope this can you you diagnose my problem.
Thanks for all your help thus far.
Robert