Hi there guys, I'd really appreciate it if you could help me out here.
My laptop's been badly infected, and I can only boot in safe mode with networking. If i start up normally as soon as I log in, the desktop and icons appear and I get the BSOD with a stop error.
Basically, I can't log into Vista (32bit) in normal mode without getting a BSOD
with error message:
*** STOP: 0X0000008E (0XC0000005, 0X8BDA092D, 0X9AEC2000, 0X00000000)
I ran Memtest86 on booting, and after 8 passes it came up with no errors, so I'm pretty sure I've got no RAM problem.
My firefox and IE browser keep on redirecting to random websites off Google search, and my problem is identical to that of this guy:
http://forums.techguy.org/malware-re...-agent-dh.html
I was seeking advice on another forum, but I havent been able to get far, and I really need my laptop back and working asap. I cant back up everything cos I dont have an external hard drive, and I need my files for exam revision

.
All my other info was posted in this forum here:
http://help.lockergnome.com/general/...pict57628.html
and that's where my HJT log and Combofix log is.
If you scroll down right to the bottom of that thread, you'll see that combofix identified the files associated with rookit activity on my laptop, but somehow i can't manage to find them myself.
....system32\drivers\ovfsthtfgkfvcnclgcieugcxojfqddrujvnucv.sys
.....system32\ovfsthgrkjtwcitydgkxveulvrbpbicvxeoxcx.dll
.....system32\ovfsthipttgjoejxtdqjnutsmincvobgvulgyg.dll
.....system32\ovfsthilbqrsjabinyjeikjejopxemgsmhippq.dll
.....system32\ovfsthnpnphnillkygpsllotxgvydeknvwoqwm.dat
Combofix says that because there is rootkit activity on my pc, it needs to reboot. Once i reboot my comp, i have to run combofix again, and the same message displays. I think it's occurring because I'm in safe mode.
Also i have a feeling that the first file in that list (the .sys one) is probably the reason behind my blue screen at startup. Do you know how I could locate the files and delete them?
Any help at all would be greatly appreciated. Many thanks in advance!