XP Home(32) SP2 running with Nvidia Forceware Firewall and Avast Anti-Virus.
Problem started with slow running machine. Thought that it needed good cleaning including per "friends" at Microsoft a "clean boot" to clean out old restore points. Found that I could not get the restore points removed using selective start-up and reloading original boot.ini. The system just keep coming back with new restore points even though "system restore was turned off. Tried to delete restore point with Malwarebytes' Anti-Malware tools. The restore points kept coming back. Also many "memory error screens" were popping up.
Then tried to start in safe mode. Found I had a new user at log in. Aviatar of a "skateboarder" with user name "Administrator" (My Admin name is different and unique.
1.Ran Malwarebytes' Anti-Malware scan found file "cryptsvc" and "userint.exe" in register. Deleted them. they came back several time, but I think I had finaly gotten rid of them. Also I turned off the Window Office language/speech app "ctfmon.exe" as it kept interrupting in the tasksbar, read somewhere it might be infected, and I don't use need it.
2.Rebooted and then things got ugly. First the was a CMD.COM script from a file "SDRA64.EXE" that started to run. I think I killed it in time.
3.Then I found a file in reg named crypt.exe. I killed it.
4. Then when windows opened I got "Windows needs to be activated" box and now a nag screen. (Called M/S and they said it was a valid install number, but I didn't reactivate because I know it is bogus)
5. My Avast A/V was dead. Reinstalled it several time and finally got it to work, it think.
6. My Firewall went dead. Window would not let me turn it back on. Finally got it back working also.
I have run: Windows Safety Scanner, Malwarebytes A/V, Spybot S/D, Avast A/V,and Rkill.exe, several times. All show system clean. None will work at boot time though.
And my other user "Skateboarder" it still showing up when I open in safe mode. I still can not delete or turn off system restore. I am still getting Windows activation nag screen. I can not get any A/V to run at boot. So I know I am still infected. I have google this bug and don't seem to find it. Does this look familiar?
I am stuck and exhausted (I am an old guy). Any help is appreciated.
Jay ( R O H D D "at" H o T m A $ L )
Attached are the DDS.Txt, Attach.Txt, Gmer_rootkit_scan.log, and Hijackthis.log files