Ran RKill again for the fun of it. I'm posting the newest results first...as you'll see it keeps finding the same thing.
Rkill 2.4.3 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/Copyright 2008-2012 BleepingComputer.com
More Information about Rkill can be found at this link:
http://www.bleepingcomputer.com/forums/topic308364.htmlProgram started at: 10/11/2012 07:25:54 PM in x86 mode.
Windows Version: Microsoft Windows XP Service Pack 3
Checking for Windows services to stop:
* No malware services found to stop.
Checking for processes to terminate:
* C:\WINDOWS\system32\MsPMSPSv.exe (PID: 2288) [WD-HEUR]
* C:\DOCUME~1\Owner1\LOCALS~1\Temp\RoboForm\RoboTaskBarIcon.exe (PID: 2712) [T-HEUR]
2 proccesses terminated!
Checking Registry for malware related settings:
* No issues found in the Registry.
Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
Performing miscellaneous checks:
* Windows Firewall Disabled
[HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = dword:00000000
Checking Windows Service Integrity:
* RpcSs => %SystemRoot%\system32\svchost.exe -k rpcss [Incorrect ImagePath]
Searching for Missing Digital Signatures:
* No issues found.
Checking HOSTS File:
* HOSTS file entries found:
127.0.0.1 localhost
Program finished at: 10/11/2012 07:26:59 PM
Execution time: 0 hours(s), 1 minute(s), and 4 seconds(s)
EARLIER RESULT
Rkill 2.4.3 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/Copyright 2008-2012 BleepingComputer.com
More Information about Rkill can be found at this link:
http://www.bleepingcomputer.com/forums/topic308364.htmlProgram started at: 10/09/2012 05:16:50 PM in x86 mode.
Windows Version: Microsoft Windows XP Service Pack 3
Checking for Windows services to stop:
* No malware services found to stop.
Checking for processes to terminate:
* C:\WINDOWS\system32\CTsvcCDA.exe (PID: 472) [WD-HEUR]
* C:\WINDOWS\system32\MsPMSPSv.exe (PID: 792) [WD-HEUR]
* C:\DOCUME~1\Owner1\LOCALS~1\Temp\RoboForm\RoboTaskBarIcon.exe (PID: 3600) [T-HEUR]
3 proccesses terminated!
Checking Registry for malware related settings:
* No issues found in the Registry.
Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
Performing miscellaneous checks:
* Windows Firewall Disabled
[HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = dword:00000000
Checking Windows Service Integrity:
* RpcSs => %SystemRoot%\system32\svchost.exe -k rpcss [Incorrect ImagePath]
Searching for Missing Digital Signatures:
* No issues found.
Checking HOSTS File:
* HOSTS file entries found:
127.0.0.1 localhost
Program finished at: 10/09/2012 05:18:26 PM
Execution time: 0 hours(s), 1 minute(s), and 36 seconds(s)