Win 7 Ult-32 SP1 + updates, Avast AV + updates
was running well, then one day I noticed Avast Anti-virus tray icon no longer showing,
Windows Update was switched off, Defender was switched off,
and various other Windows settings were not how I normally have them,
but otherwise the system was functioning OK.
On rebooting it freezes during the first screen just when you would expect the switch to video driver.
I tried various things, but often they just didn’t work as expected.
Eventually used the installation disc in repair mode to restore an earlier system image and got going again,
but only till the next reboot.
Now I can get it to load in safe mode, but not with networking services.
Device Manager > View > Show Hidden Devices has flags against spldr.sys and sptd.sys
“This device is not present, is not working properly, or does not have all its drivers installed (Code 24)”.
Event Viewer shows sptd event id 4 “Driver detected an internal error in its data structures for .”
I don’t have Alcohol or Daemon Tools, but I do have Active ISO Burner.
I downloaded the installation package for SPTD to use the uninstall feature,
but it reports its is not installed, although I can see C:/windows/system32/drivers/sptd.sys
When i try to install it, sptd.sys’s timestamp is updated, but the install ends very quickly
and the uninstall still says it is not installed.
A full scan with Avast doesn’t find anything wrong.
Kapersky’s TDSSKiller is suspicious of 4 unsigned drivers,
one of which (a ViMicro webcam driver that didn’t work) I allowed it to delete, with no effect.
HijackThis reports O20 AppInit_dlls: [blank]
which is very suspicious, but without being able to see the thing that is hiding itself, I cannot delete it.
SFC /scannow is clean.
CHKDSK C: finds errors in MFT mirror - the volume bitmap is incorrect.
CHKDSK C: /f cannot lock the volume, and on reboot it freezes before chkdsk starts.
I have 3 physical drives, SSD, SATA, USB and I have tried each one on its own, SSD and SATA do the same thing, USB(external SATA) nothing at all.
I have loaded an old PATA drive on its own and that works.
Can anyone identify the malware from that ?
Which cleaning tool(s) to use ?
Do they work in Safe Mode, because that’s all I’ve got.
It got right past Avast and switched it off :-((
This is just about the end for Windows and me.