Hi, i did a scan with AVG and it came up with this:
detection name: i8042prt.sys, hooked import HAL.dll READ_PORT_UCHAR - sphn.sys +0x11B90
description C:\windows\system32\drivers\sphn.sys
severity: medium
state: infected
source: anti-rootkit
Then I tried to remove it and it didn't
Downloaded aswMBR the log says:
aswMBR version 0.9.9.1707 Copyright(c) 2011 AVAST Software
Run date: 2013-02-14 17:38:03
-----------------------------
17:38:03.156 OS Version: Windows 5.1.2600 Service Pack 3
17:38:03.156 Number of processors: 2 586 0x1C02
17:38:03.156 ComputerName: HPMINI110-1111T UserName: Brendon
17:38:05.140 Initialize success
18:00:48.921 AVAST engine defs: 13021304
18:01:01.531 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0
18:01:01.531 Disk 0 Vendor: WDC_WD16 13.0 Size: 152627MB BusType: 3
18:01:01.562 Disk 0 MBR read successfully
18:01:01.562 Disk 0 MBR scan
18:01:01.625 Disk 0 Windows XP default MBR code
18:01:01.625 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 152617 MB offset 63
18:01:01.640 Disk 0 scanning sectors +312560640
18:01:01.734 Disk 0 scanning C:\WINDOWS\system32\drivers
18:01:23.812 Service scanning
18:01:45.703 Service sptd C:\WINDOWS\System32\Drivers\sptd.sys **LOCKED** 32
18:01:52.593 Modules scanning
18:01:59.078 Disk 0 trace - called modules:
18:01:59.078 ntkrnlpa.exe CLASSPNP.SYS disk.sys iaStor.sys spuh.sys hal.dll >>UNKNOWN [0x8a6b5938]<<
18:01:59.078 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a6f4030]
18:01:59.093 3 CLASSPNP.SYS[ba0e8fd7] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-0[0x8a6f5030]
18:01:59.828 AVAST engine scan C:\WINDOWS
18:02:05.390 AVAST engine scan C:\WINDOWS\system32
18:07:29.828 AVAST engine scan C:\WINDOWS\system32\drivers
18:08:00.359 AVAST engine scan C:\Documents and Settings\Brendon
18:18:21.718 AVAST engine scan C:\Documents and Settings\All Users
18:20:45.375 Scan finished successfully
18:56:49.593 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Brendon\My Documents\MBR.dat"
18:56:49.593 The log file has been saved successfully to "C:\Documents and Settings\Brendon\My Documents\aswMBR.txt"
Tried to fix the MBR but on reboot the rookit is still there so I need some help to remove it thanks heaps