I went through the renaming strategy, but that did not work. I then ran Rootrepeal and posted the log. Apparently, there was a rootkit in the log. I was then advised to run Win32kDiag.exe and post the log in this forum. However, there wasn't much of a log. All that was written is as follows:
Running from: C:\Documents and Settings\Brian\Desktop\Win32kDiag.exe
Log file at : C:\Documents and Settings\Brian\Desktop\Win32kDiag.txt
WARNING: Could not get backup privileges!
Searching 'C:\WINDOWS'...
Finished!
Help!!!! I want my computer back!!
Pasting in Root Repeal log from other topic. ~ OB
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/10/10 15:37
Program Version: Version 1.3.5.0
Windows Version: Windows XP Media Center Edition SP3
==================================================
Drivers
-------------------
Name: catchme.sys
Image Path: C:\ComboFix\catchme.sys
Address: 0xA8FA8000 Size: 31744 File Visible: No Signed: -
Status: -
Name: Combo-Fix.sys
Image Path: Combo-Fix.sys
Address: 0xF7667000 Size: 60416 File Visible: No Signed: -
Status: -
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xA8AFA000 Size: 98304 File Visible: No Signed: -
Status: -
Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF79C5000 Size: 8192 File Visible: No Signed: -
Status: -
Name: PROCEXP90.SYS
Image Path: C:\WINDOWS\system32\Drivers\PROCEXP90.SYS
Address: 0xF79F1000 Size: 6464 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xA7279000 Size: 49152 File Visible: No Signed: -
Status: -
Hidden/Locked Files
-------------------
Path: C:\hiberfil.sys
Status: Locked to the Windows API!
Path: c:\windows\temp\sqlite_dvo1dijikckffqd
Status: Allocation size mismatch (API: 4096, Raw: 0)
Path: c:\windows\temp\mcmsc_8pv2saa3z8nsjbh
Status: Allocation size mismatch (API: 4096, Raw: 0)
Path: c:\windows\temp\mcmsc_9dqv6xumzrza8gn
Status: Allocation size mismatch (API: 4096, Raw: 0)
Path: c:\windows\temp\mcmsc_9ujavb4fy5grygt
Status: Allocation size mismatch (API: 4096, Raw: 0)
Path: c:\documents and settings\brian\local settings\temp\~df6561.tmp
Status: Allocation size mismatch (API: 24576, Raw: 0)
Path: c:\documents and settings\brian\local settings\temp\~dfd20a.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)
==EOF==
Edited by Orange Blossom, 11 October 2009 - 12:24 AM.