When I first got this infection I had popup for PCHEALTH app which stated I had a infection and needed to clean it by downloading their program, which I did not do. I tried running several tools to remove viruses but they all seem to start to run then quit with no log files and the next time I try to run a window comes up and says 'Windows cannot access the specified device, path, or file. You may not have the appropriate permissions to access them'.
Currently I can boot in normal mode but everything takes 20 to 30 minutes to come up. I am currently in safe mode with networking.
I started to follow the Malware cleaning guide, but could not preform most of the steps for the above reason. I was able to get a log file from RootRepeal:
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/09/24 08:25
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================
Drivers
-------------------
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xF6D93000 Size: 98304 File Visible: No Signed: -
Status: -
Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF7A4B000 Size: 8192 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xF6696000 Size: 49152 File Visible: No Signed: -
Status: -
Name: win32k.sys:1
Image Path: C:\WINDOWS\win32k.sys:1
Address: 0xF78DB000 Size: 20480 File Visible: No Signed: -
Status: -
Name: win32k.sys:2
Image Path: C:\WINDOWS\win32k.sys:2
Address: 0xF714B000 Size: 61440 File Visible: No Signed: -
Status: -
SSDT
-------------------
#: 041 Function Name: NtCreateKey
Status: Hooked by "Lbd.sys" at address 0xf757387e
#: 247 Function Name: NtSetValueKey
Status: Hooked by "Lbd.sys" at address 0xf7573bfe
Hidden Services
-------------------
Service Name: UACd.sys
Image Path: C:\WINDOWS\system32\drivers\UACykridudqpq.sys
Currently I can only run in Safe mode as normal mode is too slow.
Any help would be greatly appreciated.