Hello, no I believe we are clean. But I need you to ask in the XP forum about installing SP3.
Perhaps the cleaned file here is not exactly the one you need.
Repeat this info
I created a restore point like you said. But when i tried to install SP3 I got stopped part way saying that C:/windows/system32/drivers/atapi.sys is open or in use by another program and that i need to shut down all other applications and try again. I thought i had everything shut down and i don't know why i'm getting that message.
And then when i got back on the internet to submit a reply my computer crashed witht a blue screen (BSOD) with a stop code:
0x0000008E (OxC0000005, 0xEE3085C8, 0xF7607CC, 0x00000000)And this from your killer log
2010/11/25 19:52:24.0687 Detected object count: 1
2010/11/25 19:52:44.0984 atapi (4073b90903dae8c8d6f73fbe0d529acd) C:\WINDOWS\system32\DRIVERS\atapi.sys
2010/11/25 19:52:44.0984 Suspicious file (Forged): C:\WINDOWS\system32\DRIVERS\atapi.sys. Real md5: 4073b90903dae8c8d6f73fbe0d529acd, Fake md5: 41d9cc841a47f64a855225e42dcd8523
2010/11/25 19:52:47.0734 Backup copy found, using it..
2010/11/25 19:52:48.0390 C:\WINDOWS\system32\DRIVERS\atapi.sys - processing error
2010/11/25 19:52:48.0390 Rootkit.Win32.TDSS.tdl3(atapi) - User select action: Cure
2010/11/25 19:53:30.0203 Deinitialize success
Edited by boopme, 27 November 2010 - 07:58 PM.