spyware rootkit Windows XP home

I have spyware on on windows XP home sp3 computer I can't seem to remove. HJT and Combofix logs attached. Each time I run combofix it detects a rootkit and restarts the machine before running but fails to remove the malware. I have read the log file but don't recognize the problem.
hijackthis.log
ComboFix.txt
LVL 7
rettif9DaleAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

edbedbCommented:
I would boot from a live CD like UBCD and replace these files with known good copies.  CLASSPNP.SYS, ACPI.sys, atapi.sys, ntkrnlpa.exe, NDIS.sys
0
rockiroadsCommented:
probably trying to remove before windows kicks in.

have u tried running this in safe mode? you got malware bytes also so give that a go.

some people here mention hitman pro maybe give that a go

did u also try the other tools like tddskiler http://support.kaspersky.com/viruses/solutions?qid=208280684 and rootalyzer http://forums.spybot.info/showthread.php?t=24185
0
rettif9DaleAuthor Commented:
@ edbedb - this is the only Home machine I have access to at the moment. Would it be ok to copy those files from an XP pro workstation?
@ rockiroads - I should have mentioned I have already run Spybot S&D, Malwarebytes, and Superantispyware. I have run combofix normally and in safemode with the same result each time. I'll try the other tools you mentioned.
0
Ultimate Tool Kit for Technology Solution Provider

Broken down into practical pointers and step-by-step instructions, the IT Service Excellence Tool Kit delivers expert advice for technology solution providers. Get your free copy now.

edbedbCommented:
Xp Pro should be fine as long as it is SP3
0
optomaCommented:
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
rettif9DaleAuthor Commented:
@ edbedb - I copied the listed files to the folders I found them in but it had no effect.

@ all - I followed the instructions in KB article 971058 two of the dll files could not be found. I checked another machine (working) and it didn't have them either. wucltux.dll and wuwebv.dll FYI

@ optoma installed and ran hitmanpro and it did it. It found another rootkit in the MBR sorry guys I forgot to write down the name of the little bugger but the machine is running MS updates as I type.

Thanks to everyone for their efforts.
0
rettif9DaleAuthor Commented:
the instructions in the KB article had no effect....
0
rockiroadsCommented:
glad your all sorted. big relief. so did you try all the tools I suggested then? even hitman pro which is what I also suggested? maybe should of given you the link then
0
optomaCommented:
@ Rockiroads. Sorry. I overlooked that you mentioned Hitmanpro :(
0
rettif9DaleAuthor Commented:
@ rockiroads - My apologies, you did mention hitmanpro first and I should have at least shared the  points. I simply overlooked it.

rettif9
0
rettif9DaleAuthor Commented:
@ rockiroads - just FYI I did try rootalyzer and tddskiler without success.
0
rockiroadsCommented:
no probs, good idea to keep note of all the tools mentioned in case you get something again.
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Anti-Virus Apps

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.