BOClean finds this:
03/20/2008 17:08:47: BUSHBOT MALWARE STOPPED by BOCLEAN!
Trojan horse was found in memory.
E:\GAMES\SKULLTAG\ZDL.EXE contained the trojan.
Active trojan horse WAS shut down. System now safe.
Then BOClean stops me from loading IE7, then causes the following error below in which when I tried to restart XP it ends up stopping XP from booting, so had to use Last known configuration, to get XP to boot again and had to remove BOClean in safe mode.
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7000
Date: 20/03/2008
Time: 17:26:16
User: N/A
Computer: ASUS
Description:
The BOClean Kernel Monitor. service failed to start due to the following error:
The system cannot find the file specified.
For more information, see Help and Support Center at Microsoft Support.
Help and Support Centre information:
Details
Product: Windows Operating System
ID: 7000
Source: Service Control Manager
Version: 5.0
Symbolic Name: EVENT_SERVICE_START_FAILED
Message: The %1 service failed to start due to the following error:
%2.
Explanation
Service Control Manager (SCM) could not start the specified service, probably because the service is not configured correctly.
User Action
Do one or all of the following:
Review the error information displayed in the message.
Verify that the service password has not expired.
Verify that the service is in the correct location.
Verify that the service is not infected with a virus.
To display the WIN32_EXIT_CODE error that SCM encountered when trying to start the program, at the command prompt, type
sc query service name
The information displayed can help you troubleshoot possible causes for the error.
If the WIN32_EXIT_CODE is zero, then SCM did not attempt to start the service because the error was detected first.
Version: 5.2
Symbolic Name: EVENT_SERVICE_START_FAILED
Message: The %1 service failed to start due to the following error:
%2
Explanation
Service Control Manager (SCM) could not start the specified service, probably because the service is not configured correctly.
User Action
Do one or all of the following:
Review the error information displayed in the message.
Verify that the service password has not expired.
Verify that the service is in the correct location.
Verify that the service is not infected with a virus.
To display the WIN32_EXIT_CODE error that SCM encountered when trying to start the program, at the command prompt, type
sc query service name
The information displayed can help you troubleshoot possible causes for the error.
If the WIN32_EXIT_CODE is zero, then SCM did not attempt to start the service because the error was detected first.
And I was running the latest version of BOClean as well.