Avast! is showing this popup:
MALICIOUS URL BLOCKED
avast! Network Shield has blocked a harmful site
Object: hxxp://xxxxxxxxx.com/x/
Infection: URL:Mal
Process: C:\WINDOWS\System32\svchost.exe
It seem to be adware trying to call home. It’s trying to connect with 5 or 6 different sites, e.g., credit, loans, merchant accounts, etc.
Neither avast! nor MBAM appear to be able to find it.
I’ve posted and attached the logs.
Help will be appreciated!
=================
Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org
Database version: v2012.12.16.06
Windows XP Service Pack 3 x86 NTFS (Safe Mode)
Internet Explorer 8.0.6001.18702
Louis :: POWERHORSE [administrator]
12/17/12 10:04:33 AM
mbam-log-2012-12-17 (10-04-33).txt
Scan type: Full scan (C:|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 557305
Time elapsed: 2 hour(s), 45 minute(s), 57 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
=================
aswMBR version 0.9.9.1707 Copyright(c) 2011 AVAST Software
Run date: 2012-12-18 04:05:11
04:05:11.703 OS Version: Windows 5.1.2600 Service Pack 3
04:05:11.703 Number of processors: 1 586 0x602
04:05:11.703 ComputerName: POWERHORSE UserName:
04:05:31.984 Initialize success
04:06:20.125 AVAST engine defs: 12121700
04:06:26.343 Disk 0 (boot) \Device\Harddisk0\DR0 → \Device\Ide\IdeDeviceP0T0L0-4
04:06:26.343 Disk 0 Vendor: ST3120026A 8.01 Size: 114473MB BusType: 3
04:06:26.390 Disk 1 \Device\Harddisk1\DR1 → \Device\Ide\IdeDeviceP0T1L0-c
04:06:26.421 Disk 1 Vendor: ST340016A 3.21 Size: 38166MB BusType: 3
04:06:26.421 Device \Driver\atapi → DriverStartIo 876c12e2
04:06:26.437 Disk 0 MBR read successfully
04:06:26.437 Disk 0 MBR scan
04:06:36.203 Disk 0 Windows XP default MBR code
04:06:36.218 Disk 0 MBR hidden
04:06:36.328 Disk 0 Partition 1 00 07 HPFS/NTFS NTFS 114470 MB offset 63
04:06:43.375 Disk 0 scanning sectors +234435600
04:06:46.843 Disk 0 scanning C:\WINDOWS\system32\drivers
04:08:43.640 Service scanning
04:09:46.359 Modules scanning
04:09:58.140 Disk 0 trace - called modules:
04:09:58.156 ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x876c14b1]<<
04:09:58.187 1 nt!IofCallDriver → \Device\Harddisk0\DR0[0x8774dab8]
04:09:58.187 3 CLASSPNP.SYS[f785dfd7] → nt!IofCallDriver → [0x876bb8f0]
04:09:58.203 \Driver\atapi[0x876bcdb8] → IRP_MJ_CREATE → 0x876c14b1
04:10:01.921 AVAST engine scan C:\WINDOWS
04:10:38.796 AVAST engine scan C:\WINDOWS\system32
04:19:32.609 AVAST engine scan C:\WINDOWS\system32\drivers
04:20:02.500 AVAST engine scan C:\Documents and Settings\Louis
04:39:41.515 AVAST engine scan C:\Documents and Settings\All Users
04:42:08.046 Scan finished successfully
04:42:26.718 Disk 0 MBR has been saved successfully to “C:\Documents and Settings\Louis\Desktop\MBR.dat”
04:42:26.718 The log file has been saved successfully to “C:\Documents and Settings\Louis\Desktop\aswMBR.txt”
aswMBR version 0.9.9.1707 Copyright(c) 2011 AVAST Software
Run date: 2012-12-18 04:05:11
04:05:11.703 OS Version: Windows 5.1.2600 Service Pack 3
04:05:11.703 Number of processors: 1 586 0x602
04:05:11.703 ComputerName: POWERHORSE UserName:
04:05:31.984 Initialize success
04:06:20.125 AVAST engine defs: 12121700
04:06:26.343 Disk 0 (boot) \Device\Harddisk0\DR0 → \Device\Ide\IdeDeviceP0T0L0-4
04:06:26.343 Disk 0 Vendor: ST3120026A 8.01 Size: 114473MB BusType: 3
04:06:26.390 Disk 1 \Device\Harddisk1\DR1 → \Device\Ide\IdeDeviceP0T1L0-c
04:06:26.421 Disk 1 Vendor: ST340016A 3.21 Size: 38166MB BusType: 3
04:06:26.421 Device \Driver\atapi → DriverStartIo 876c12e2
04:06:26.437 Disk 0 MBR read successfully
04:06:26.437 Disk 0 MBR scan
04:06:36.203 Disk 0 Windows XP default MBR code
04:06:36.218 Disk 0 MBR hidden
04:06:36.328 Disk 0 Partition 1 00 07 HPFS/NTFS NTFS 114470 MB offset 63
04:06:43.375 Disk 0 scanning sectors +234435600
04:06:46.843 Disk 0 scanning C:\WINDOWS\system32\drivers
04:08:43.640 Service scanning
04:09:46.359 Modules scanning
04:09:58.140 Disk 0 trace - called modules:
04:09:58.156 ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x876c14b1]<<
04:09:58.187 1 nt!IofCallDriver → \Device\Harddisk0\DR0[0x8774dab8]
04:09:58.187 3 CLASSPNP.SYS[f785dfd7] → nt!IofCallDriver → [0x876bb8f0]
04:09:58.203 \Driver\atapi[0x876bcdb8] → IRP_MJ_CREATE → 0x876c14b1
04:10:01.921 AVAST engine scan C:\WINDOWS
04:10:38.796 AVAST engine scan C:\WINDOWS\system32
04:19:32.609 AVAST engine scan C:\WINDOWS\system32\drivers
04:20:02.500 AVAST engine scan C:\Documents and Settings\Louis
04:39:41.515 AVAST engine scan C:\Documents and Settings\All Users
04:42:08.046 Scan finished successfully
04:42:26.718 Disk 0 MBR has been saved successfully to “C:\Documents and Settings\Louis\Desktop\MBR.dat”
04:42:26.718 The log file has been saved successfully to “C:\Documents and Settings\Louis\Desktop\aswMBR.txt”
04:49:28.312 Disk 0 MBR has been saved successfully to “C:\Documents and Settings\Louis\Desktop\MBR.dat”
04:49:28.328 The log file has been saved successfully to “C:\Documents and Settings\Louis\Desktop\aswMBR.txt”
=================