i also ran Trend Micro Rootkit Buster and it flagged up 30 hidden files but it too said it was unable to delete them. here's the log that TMRB returned:
--== Dump Hidden MBR, Hidden Files and Alternate Data Streams on C:\ ==--
No hidden files found.
--== Dump Hidden Registry Value on HKLM ==--
[HIDDEN_REGISTRY][Hidden Reg Value]:
KeyPath : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Media Center\Service\Recording\Restricted
Root : 0
SubKey : Restricted
ValueName : ccc
Data : 48 E7 E 92 58 B3 13 E6 ...
ValueType : 3
AccessType: 0
FullLength: 0x66
DataSize : 0xc8
1 hidden registry entries found.
--== Dump Hidden Process ==--
No hidden processes found.
--== Dump Hidden Driver ==--
No hidden drivers found.
--== Service Win32 API Hook List ==--
[HOOKED_SERVICE_API]:
Service API : ZwAddBootEntry
Image Path : C:\Windows\System32\Drivers\aswSnx.SYS
OriginalHandler : 0x828ceec6
CurrentHandler : 0x9e51b202
ServiceNumber : 0x9
ModuleName : aswSnx.SYS
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : ZwCreateEvent
Image Path : C:\Windows\System32\Drivers\aswSnx.SYS
OriginalHandler : 0x8282bd37
CurrentHandler : 0x9e51d7f0
ServiceNumber : 0x3a
ModuleName : aswSnx.SYS
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : ZwCreateEventPair
Image Path : C:\Windows\System32\Drivers\aswSnx.SYS
OriginalHandler : 0x828d4584
CurrentHandler : 0x9e51d848
ServiceNumber : 0x3b
ModuleName : aswSnx.SYS
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : ZwCreateIoCompletion
Image Path : C:\Windows\System32\Drivers\aswSnx.SYS
OriginalHandler : 0x827e5907
CurrentHandler : 0x9e51d95e
ServiceNumber : 0x3d
ModuleName : aswSnx.SYS
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : ZwCreateMutant
Image Path : C:\Windows\System32\Drivers\aswSnx.SYS
OriginalHandler : 0x828397bc
CurrentHandler : 0x9e51d746
ServiceNumber : 0x43
ModuleName : aswSnx.SYS
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : ZwCreateSection
Image Path : C:\Windows\System32\Drivers\aswSnx.SYS
OriginalHandler : 0x8284ad95
CurrentHandler : 0x9e51d898
ServiceNumber : 0x4b
ModuleName : aswSnx.SYS
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : ZwCreateSemaphore
Image Path : C:\Windows\System32\Drivers\aswSnx.SYS
OriginalHandler : 0x827f0cc3
CurrentHandler : 0x9e51d79a
ServiceNumber : 0x4c
ModuleName : aswSnx.SYS
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : ZwCreateTimer
Image Path : C:\Windows\System32\Drivers\aswSnx.SYS
OriginalHandler : 0x827d3a9f
CurrentHandler : 0x9e51d90c
ServiceNumber : 0x4f
ModuleName : aswSnx.SYS
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : ZwDeleteBootEntry
Image Path : C:\Windows\System32\Drivers\aswSnx.SYS
OriginalHandler : 0x828ceef7
CurrentHandler : 0x9e51b226
ServiceNumber : 0x78
ModuleName : aswSnx.SYS
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : ZwLoadDriver
Image Path : C:\Windows\System32\Drivers\aswSnx.SYS
OriginalHandler : 0x82784dee
CurrentHandler : 0x9e51aff0
ServiceNumber : 0xa5
ModuleName : aswSnx.SYS
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : ZwModifyBootEntry
Image Path : C:\Windows\System32\Drivers\aswSnx.SYS
OriginalHandler : 0x828cf0c7
CurrentHandler : 0x9e51b24a
ServiceNumber : 0xb2
ModuleName : aswSnx.SYS
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : ZwNotifyChangeKey
Image Path : C:\Windows\System32\Drivers\aswSnx.SYS
OriginalHandler : 0x827d85d9
CurrentHandler : 0x9e51dd56
ServiceNumber : 0xb5
ModuleName : aswSnx.SYS
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : ZwNotifyChangeMultipleKeys
Image Path : C:\Windows\System32\Drivers\aswSnx.SYS
OriginalHandler : 0x827d7a51
CurrentHandler : 0x9e51bcda
ServiceNumber : 0xb6
ModuleName : aswSnx.SYS
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : ZwOpenEvent
Image Path : C:\Windows\System32\Drivers\aswSnx.SYS
OriginalHandler : 0x82812d5f
CurrentHandler : 0x9e51d820
ServiceNumber : 0xb8
ModuleName : aswSnx.SYS
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : ZwOpenEventPair
Image Path : C:\Windows\System32\Drivers\aswSnx.SYS
OriginalHandler : 0x828d46b3
CurrentHandler : 0x9e51d870
ServiceNumber : 0xb9
ModuleName : aswSnx.SYS
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : ZwOpenIoCompletion
Image Path : C:\Windows\System32\Drivers\aswSnx.SYS
OriginalHandler : 0x828866cd
CurrentHandler : 0x9e51d988
ServiceNumber : 0xbb
ModuleName : aswSnx.SYS
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : ZwOpenMutant
Image Path : C:\Windows\System32\Drivers\aswSnx.SYS
OriginalHandler : 0x8282aaf1
CurrentHandler : 0x9e51d772
ServiceNumber : 0xbf
ModuleName : aswSnx.SYS
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : ZwOpenSection
Image Path : C:\Windows\System32\Drivers\aswSnx.SYS
OriginalHandler : 0x8282a5fd
CurrentHandler : 0x9e51d8d8
ServiceNumber : 0xc5
ModuleName : aswSnx.SYS
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : ZwOpenSemaphore
Image Path : C:\Windows\System32\Drivers\aswSnx.SYS
OriginalHandler : 0x827beebe
CurrentHandler : 0x9e51d7c8
ServiceNumber : 0xc6
ModuleName : aswSnx.SYS
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : ZwOpenTimer
Image Path : C:\Windows\System32\Drivers\aswSnx.SYS
OriginalHandler : 0x828d430f
CurrentHandler : 0x9e51d936
ServiceNumber : 0xcc
ModuleName : aswSnx.SYS
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : ZwQueryObject
Image Path : C:\Windows\System32\Drivers\aswSnx.SYS
OriginalHandler : 0x827ff343
CurrentHandler : 0x9e51bba0
ServiceNumber : 0xed
ModuleName : aswSnx.SYS
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : ZwSetBootEntryOrder
Image Path : C:\Windows\System32\Drivers\aswSnx.SYS
OriginalHandler : 0x828cf7f8
CurrentHandler : 0x9e51b26e
ServiceNumber : 0x11f
ModuleName : aswSnx.SYS
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : ZwSetBootOptions
Image Path : C:\Windows\System32\Drivers\aswSnx.SYS
OriginalHandler : 0x828cfcfa
CurrentHandler : 0x9e51b292
ServiceNumber : 0x120
ModuleName : aswSnx.SYS
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : ZwSetSystemInformation
Image Path : C:\Windows\System32\Drivers\aswSnx.SYS
OriginalHandler : 0x827ffe83
CurrentHandler : 0x9e51b04a
ServiceNumber : 0x13d
ModuleName : aswSnx.SYS
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : ZwSetSystemPowerState
Image Path : C:\Windows\System32\Drivers\aswSnx.SYS
OriginalHandler : 0x828f30a1
CurrentHandler : 0x9e51b186
ServiceNumber : 0x13e
ModuleName : aswSnx.SYS
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : ZwShutdownSystem
Image Path : C:\Windows\System32\Drivers\aswSnx.SYS
OriginalHandler : 0x828cc3a1
CurrentHandler : 0x9e51b162
ServiceNumber : 0x146
ModuleName : aswSnx.SYS
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : ZwSystemDebugControl
Image Path : C:\Windows\System32\Drivers\aswSnx.SYS
OriginalHandler : 0x82811e51
CurrentHandler : 0x9e51b1aa
ServiceNumber : 0x14c
ModuleName : aswSnx.SYS
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : ZwVdmControl
Image Path : C:\Windows\System32\Drivers\aswSnx.SYS
OriginalHandler : 0x828c0ee3
CurrentHandler : 0x9e51b2b6
ServiceNumber : 0x15d
ModuleName : aswSnx.SYS
SDTType : 0x0
--== Dump Hidden Port ==--
No hidden ports found.
--== Dump Kernel Code Patching ==--
[KERNEL_CODE][PATCHED]:
Service API : ZwCreateProcessEx
Address : 828AADAE
CurrentCode : E9B349AA1C
ExpectedCode : 6A0C681818
ServiceNumber : 0x49
SDTType : 0x0
1 Kernel code patching found.
--== Dump Hidden Services ==--
No hidden services found.
it has also been having occasional minor bluescreen errors (or that is what it was according to the error report) where it goes to a black screen with a blue banner saying it is dumping the physical memory then boots up again.
any help at all would be greatly appreciated
cheers
Ross