DDS (Ver_2012-11-20.01) - NTFS_x86Internet Explorer: 8.0.6001.18702Run by dcs at 14:52:45 on 2013-09-09Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1980.1409 [GMT -7:00].AV: Avira Desktop *Enabled/Outdated* {AD166499-45F9-482A-A743-FDD3350758C7}.============== Running Processes ================.C:\WINDOWS\system32\spoolsv.exeC:\Program Files\Intel\ASF Agent\ASFAgent.exeC:\Program Files\Java\jre6\bin\jqs.exeC:\Rey\Bin\Ucsinsvc.exeC:\WINDOWS\Explorer.EXEC:\rey\bin\PscVersionService.exeC:\WINDOWS\system32\SearchIndexer.exeC:\Program Files\Analog Devices\Core\smax4pnp.exeC:\WINDOWS\system32\hkcmd.exeC:\WINDOWS\system32\igfxpers.exe

Spy Sweeper keeps detecting a Rootkit.

The attach.txt file did generate but I can't attach it since I had to write this on my iPad.

Could this be on the BIOS? I have attached the root kit report and D.D.S.

DDS (Ver_10-11-27.01) - NTFSx86 Run by A Smith at 22:39:44.87 on Fri 12/03/2010 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_22 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.503.222 [GMT antivirus 4.8.1368 [VPS 091216-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}============== Running Processes ===============C:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\system32\svchost -k DcomLaunchsvchost.exeC:\Program Files\Windows Defender\MsMpEng.exeC:\WINDOWS\System32\svchost.exe -k netsvcssvchost.exesvchost.exeC:\Program Files\Alwil Software\Avast4\aswUpdSv.exeC:\Program Files\Alwil Software\Avast4\ashServ.exeC:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Multimedia Keyboard\KbdAp32A.exeC:\Program Files\Browser Mouse\mouse32a.exeC:\Program Files\Alwil Software\Avast4\ashDisp.exeC:\Program Files\Microsoft ActiveSync\WCESCOMM.EXEsvchost.exeC:\WINDOWS\System32\svchost.exe -k

O/S: Windows XP Pro SP3 (no install or boot disk)

I have run DDS and GMER and it indicates possible TDL3 rootkit infection. i also read where you can boot up with the 'XP-CD", go into recovery console, click on "fixmbr" & it will delete the old mbr file along with the mbr rootkit

AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095} . ============== Running Processes =============== . So please do not use slang or idioms. Type temp and clear everything out of that folder and then repeat opening run and type %temp% and delete everything in that folder.

Rootkit variant confirmed by Boopme

AdAware detected the rootkit specified in the post title, and what sound like radio ads are playing even when I have no programs running. DDS (Ver_10-11-27.01) - NTFSx86 Run by A Smith at 22:39:44.87 on Fri 12/03/2010Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_22Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.503.222 [GMT -5:00]AV: AVG Anti-Virus Free

However, browsing and performance are sluggish.

I still see files in my Registry. Very long log posted below FYI. I assume the root kit is causing this.