I am here out of sheer desperation. I have been working on my father-in-laws laptop for the past 2.5 days and I am now officially over it.
I have been following a few of your links and recommendations but to no avail. I am hoping that you may be able to point me in the right direction and finally fix this for me.
So far the below is what has been carried out:
Computer boots with an error message stating that worm.netsky32(blah blah) has been detected.
1. F-I-L (father-in-law) carried out a virus scan with clamwin. Found 2,500 affected files. Restarted machine, ran the scan again hoping that the files were removed = alas no, then restarted and got an error
<A problem is preventing windows from accurately checking the license for this computer. Error code 0x80090006. [OK]>
Click [OK]
Goes to desktop with no icons, no start bar, nadda...
2. I removed the hard drive and have placed it into an external casing and have run an AVG virus scan. Found 3000 files affected. Removed all files. Tried to restart - got the same error message <A problem is preventing windows from accurately checking the license for this computer. Error code 0x80090006. [OK]> [/color]and desktop location.
3. Located your OTL scan\fix
Ran this with pasting a few different recommendations from you (an old hacker at heart thought i could fix this myself but to no avail)
At least I can now get to the hard drive and view it as c:\
4. Ran Symmantec netsky fix file only to be told that no netsky virus was found. {okie dokie}
5. Then consulted your Malware and Spyware Cleaning Guide and followed the instructions.
Ran Smitfraudfix - loaded it - a flash on the screen then nothing
Ran MBAM - tried to load but get an access is denied error mesage as it is trying to look to x:\i386\system32\drivers\mbamswissarmy.sys {even though I pointed it to run to c:\ ???} then got <An error occurred. Please report the following error code to the Malwarebytes anti-malware support team. Error code: 723 (2, 0) The system can not find the file specified.
Ran Gmer - log available below
Ran OTL - logs available below
Logs are as follows:
Gmer:
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit quick scan 2010-02-17 14:30:55
Windows 5.1.2600
Running: gmer.exe; Driver: B:\uwtdrpoc.sys
---- Threads - GMER 1.0.15 ----
Thread System [4:144] F6D39178
Thread System [4:148] F6C6D096
---- EOF - GMER 1.0.15 ----
=================================
[color="#000000"]
Error: Unable to interpret <netsvcs> in the current context!
Error: Unable to interpret <%SYSTEMDRIVE%\*.exe> in the current context!
Error: Unable to interpret </md5start> in the current context!
Error: Unable to interpret <eventlog.dll> in the current context!
Error: Unable to interpret <scecli.dll> in the current context!
Error: Unable to interpret <netlogon.dll> in the current context!
Error: Unable to interpret <cngaudit.dll> in the current context!
Error: Unable to interpret <sceclt.dll> in the current context!
Error: Unable to interpret <ntelogon.dll> in the current context!
Error: Unable to interpret <logevent.dll> in the current context!
Error: Unable to interpret <iaStor.sys> in the current context!
Error: Unable to interpret <nvstor.sys> in the current context!
Error: Unable to interpret <atapi.sys> in the current context!
Error: Unable to interpret <IdeChnDr.sys> in the current context!
Error: Unable to interpret <viasraid.sys> in the current context!
Error: Unable to interpret <AGP440.sys> in the current context!
Error: Unable to interpret <vaxscsi.sys> in the current context!
Error: Unable to interpret <nvatabus.sys> in the current context!
Error: Unable to interpret <viamraid.sys> in the current context!
Error: Unable to interpret <nvata.sys> in the current context!
Error: Unable to interpret <nvgts.sys> in the current context!
Error: Unable to interpret <iastorv.sys> in the current context!
Error: Unable to interpret <ViPrt.sys> in the current context!
Error: Unable to interpret <eNetHook.dll> in the current context!
Error: Unable to interpret <ahcix86.sys> in the current context!
Error: Unable to interpret <KR10N.sys> in the current context!
Error: Unable to interpret <nvstor32.sys> in the current context!
Error: Unable to interpret <ahcix86s.sys> in the current context!
Error: Unable to interpret <nvrd32.sys > in the current context!
Error: Unable to interpret <symmpi.sys> in the current context!
Error: Unable to interpret <adp3132.sys> in the current context!
Error: Unable to interpret <mv61xx.sys> in the current context!
Error: Unable to interpret </md5stop> in the current context!
Error: Unable to interpret <%systemroot%\*. /mp /s> in the current context!
Error: Unable to interpret <CREATERESTOREPOINT> in the current context!
Error: Unable to interpret <%systemroot%\system32\*.dll /lockedfiles> in the current context!
Error: Unable to interpret <%systemroot%\Tasks\*.job /lockedfiles> in the current context!
Error: Unable to interpret <%systemroot%\system32\drivers\*.sys /lockedfiles> in the current context!
Error: Unable to interpret <%systemroot%\System32\config\*.sav > in the current context!
OTLPE by OldTimer - Version 3.1.29.0 log created on 02172010_140857
Any help you can offer is sooooooo greatly appreciated.
Thanks in advance.
Cheers
Nic