It looks like I am not the only one with this problem as there are a few other topics on this. Apologies that I haven't been able to find the cure in those posts, but hopefully someone can walk me through it. ... and I'm running windows XP.
Here's the history. ... the first thing that i noticed last Friday (I believe) was that my gigabyte audio panel kept saying new device installed for the speakers. I thought nothing of it and thought it was a loose cord. (and it still could be completely unrelated).
Sunday I started getting the fake windows security alert popups. That was due to ave.exe and I think that I mostly manually took care of that and "contained" it.
However at the same time random sites were popping up in new tabs in firefox. I close them before they load if I am not familiar with the sites so I can not tell you which sites they are, but I am sure they can't be great sites.
Also, Google links are redirecting. That is still occurring.
This is what I have done and figured out.
First, I manually took out ave.exe, other programs finished the job (see below)
I ran system scan with Mcafee OAS - nothing found.
Downloaded and ran adaware - nothing found.
downloaded and ran Dr. Web cure it. It found tddsrootkit in the memory (svchosts) and killed it, but nothing more.
Downloaded and ran tddskiller from kaspersky. It found one Tdds rootkit still in the memory and one in a file and didn't get rid of either.
Downloaded and ran Stinger which finished the job on Ave.exe and killed Dr.Web and tddskiller. But it did nothing with the other problems.
From what I can tell the nvidia driver running the MCP61 Serial ATA Controller is infected - File ...drivers\nvata.sys
my ... drivers\etc\hosts file is fine, but that's the only one I checked.
Also another weird issue is that I can not start up in safe mode. When I try to reboot in safe mode, I hit F8 and once i get into the DOS prompts, my USB wireless keyboard, or my USB wired keyboard does not talk to the computer.
Lastly, when I look at device manager I find nothing containing the name 'TDSS' and nothing irregular, except that I have two entries for the serial ATA controller (and others).
So right now google is redirecting and I'm infrequently getting new tabs opening loading "random pages."
Any ideas and/or help would be great. Basic instructions are ideal as I know just enough about the operating system to get me into loads and loads of trouble!
Thanks!